Splunk Enterprise

Incremental increase in memory usage

khj
Explorer

I installed Splunk Add-on for Google Cloud Platform and set it up like this, and it keeps increasing until the memory usage reaches 99% at around 15% per day. I haven't found any specific reason, but it's been happening since I set it up for collection in that app. Is there anything wrong with that app?

Splunk Add-on for Google Cloud Platform 4.7.2
Average daily collection: 10G

[Setting up]
input type : Cloud Pub/Sub Based Bucket
Number of Threads : 10
Interval: 0

[system env]
CPU: Intel (R) Xeon (R) Platinum 8488C, 8Cores
Memory : 32 G

Labels (1)
0 Karma
1 Solution

livehybrid
SplunkTrust
SplunkTrust

Hi @khj 

Your server specs look more than enough to cover this and it seems the app is intended to be run with the interval=0 set as it runs continuously. I think the best approach here would be to file a support case at https://www.splunk.com/support because this is a Splunk supported app, they should hopefully be able to validate things and hopefully remediate either through settings updates or a fix to the app itself if required.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

 

View solution in original post

livehybrid
SplunkTrust
SplunkTrust

Hi @khj 

Your server specs look more than enough to cover this and it seems the app is intended to be run with the interval=0 set as it runs continuously. I think the best approach here would be to file a support case at https://www.splunk.com/support because this is a Splunk supported app, they should hopefully be able to validate things and hopefully remediate either through settings updates or a fix to the app itself if required.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

 

Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...