Splunk ITSI

Muliple JAVA process on ITSI server

ips_mandar
Builder

HI,
I have dedicated serach head for ITSI on windows OS. I have ITSI version 4.0.4 and I have installed Java SE Development Kit 8. But when itry to create notable event aggregation policies then multiple java instance are running which in turn CPU utilization goes to 100.
so what can be issue due to which multiple java process are running?
I would appreciate any ideas?
it seems hardware is enough but not understand about multiple java instance..
Thanks

0 Karma

srinivasmanikan
Engager

That Java processes are created by rules engine
rules engine is used by grouping policy
In this case we have to go to the scheduled search and there we have ITSI_Event_grouping
we need to kill this job so it will again restart the job then our CPU comes down

0 Karma

skoelpin
SplunkTrust
SplunkTrust

You probably don't want to hear this, but you should run it on *nix. I would recommend opening a support case

0 Karma
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Building Momentum: Splunk Developer Program at .conf25

At Splunk, developers are at the heart of innovation. That’s why this year at .conf25, we officially launched ...