Splunk Enterprise

Receiving errors after upgrading to 8.2.4, like "Sum of 3 Highest per-cpu iowaits reached red Threshold of 15"

SamHTexas
Builder

I get the following after upgrading to Splunk 8.2.4 on Splunk Ent. + ES. I have a large environment with clustered SHs & Indexers. Thank u for your reply in advance.

"Sum of 3 Highest per-cpu iowaits reached red Threshold of 15" on ES

"Maximum per-cpu iowait reached yellow Threshold of 5" on  Search heads

What do they mean & How do I fix the issues please.

 

Labels (1)
Tags (1)
0 Karma

Stefanie
Builder

We get the same error on our environment too. I've reached out to Splunk Support a few times to get clarification on this.

Is your environment virtualized by chance? Basically this error means you are lacking on your resources. 

CPU iowait means that the CPU was idle during which the system had pending disk I/O requests. Basically the CPU is like "Hey! I have stuff I could be processing but I'm stuck waiting for x, y, and z to complete!"

How to resolve? An upgrade to your storage devices for faster throughput or if you're virtualized, possibly dedicating your virtual resources to Splunk servers.

Depending on how heavy your users are to Splunk - It's relatively harmless. But you may need to look at increasing resources in the future.

Refer to https://docs.splunk.com/Documentation/Splunk/8.2.4/Capacity/Referencehardware for more information on what you should be utilizing for your Splunk servers.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...