Splunk ITSI

How to threshold Processor Queue Length in Splunk ITSI?

Kendo213
Communicator

How are you guys thresholding Processor Queue Length in ITSI? ITSI by default has static thresholds that don't necessarily make sense.

Normal: 0-1, Medium: 2-5, High: >5

Information I've read states that if the processor queue length is twice the number of cores it should be a concern. If a system has 16 cores and 5 processor queue length, I wouldn't think that would be an issue based on information I've read.

0 Karma

yannK
Splunk Employee
Splunk Employee

It sounds like a Microsoft admin question.
Those data seem to be from a windows forwarder monitoring, but microsoft explains that the number depends of the number of cores.

Microsoft® Description – Processor Queue Length is the number of threads in the processor queue. Unlike the disk counters, this counter counters, this counter shows ready threads only, not threads that are running. There is a single queue for processor time even on computers with multiple processors. Therefore, if a computer has multiple processors, you need to divide this value by the number of processors servicing the workload. A sustained processor queue of less than 10 threads per processor is normally acceptable, dependent of the workload.

Maybe you could use an more complex KPI search to also compare the number of cores, and normalize your metric.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – August 2026

MichelleCorpora_1-1788182384472.png Welcome to the August 2026 edition of Data Management Digest! August was a ...

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...