Splunk Enterprise

Why doesn't splunk recognize our second CPU?

Gregski11
Contributor

All our search heads have dual processors in them but Splunk seems to only recognizes one in each of the three servers based on the number of CPU cores it reports in the Monitoring Console web gui, can Splunk use more than one processor? 

 

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Can you check what there is added to splunkd.log when splunk has started? There should be that and another information like OS etc. mentioned.

r. Ismo

0 Karma

Azeemering
Builder

Yes Splunk's Minimum search head specification's are:

  • An x86 64-bit chip architecture.
  • 16 physical CPU cores, or 32 vCPU at 2Ghz or greater speed per core.
  • 12GB RAM.

See:

Reference hardware - Splunk Documentation

 

0 Karma

Gregski11
Contributor

@Azeemering wrote:

Yes Splunk's Minimum search head specification's are:

  • An x86 64-bit chip architecture.
  • 16 physical CPU cores, or 32 vCPU at 2Ghz or greater speed per core.
  • 12GB RAM.

See:

Reference hardware - Splunk Documentation

 


thank you, but I don't follow, you shared the minimum specifications and my question was why Splunk does not see the second CPU in our machines, I followed that link and don't see how to engage the other CPU, what am I missing?

0 Karma

Azeemering
Builder

Is it a x86 64-bit chip?

Is it hyperthreaded? Hyper-threading does not add cores as far as Splunk is concerned. 

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...