Splunk IT Service Intelligence

100% CPU on Splunk Insights for Infrastructure central collector server

s2801871r
Explorer

We are seeing high CPU 100% on the server always. It is very slow. The SII is deployed on a Windows 2012 R2 server. We see that there are 6 splunkd services running average 11%. Why there are so many processes running and how can we fix this high CPU issue?

0 Karma

mattymo
Splunk Employee
Splunk Employee

Hi s2801871r!

What are the specs? Which version of SII?

What inputs have you enabled and from how many servers?

- MattyMo
0 Karma

s2801871r
Explorer

Following is the SII information:
Splunk Insights For Infrastructure

Version ..................................................................................1.1.0
Build ..................................................................................2
Server .................................................................................. 4 CPU 8 GB RAM
Splunk TA AWS Version ..................................................................................4.5.0
Splunk Version ..................................................................................7.1.0
Splunk Build ..................................................................................cc33fbdac2cf

We are have 35 entities syncing metrics. do you need any additional information?

0 Karma

mattymo
Splunk Employee
Splunk Employee

What input are the entities using (collectd? aws? windows?)

- MattyMo
0 Karma

s2801871r
Explorer

collectd from Linux and windows. No AWS.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Unified Identity - Now Available for Existing Splunk ...

Raise your hand if you’ve already forgotten your username or password when logging into an account. (We can’t ...

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...