Splunk ITSI

Muliple JAVA process on ITSI server

ips_mandar
Builder

HI,
I have dedicated serach head for ITSI on windows OS. I have ITSI version 4.0.4 and I have installed Java SE Development Kit 8. But when itry to create notable event aggregation policies then multiple java instance are running which in turn CPU utilization goes to 100.
so what can be issue due to which multiple java process are running?
I would appreciate any ideas?
it seems hardware is enough but not understand about multiple java instance..
Thanks

0 Karma

srinivasmanikan
Engager

That Java processes are created by rules engine
rules engine is used by grouping policy
In this case we have to go to the scheduled search and there we have ITSI_Event_grouping
we need to kill this job so it will again restart the job then our CPU comes down

0 Karma

skoelpin
SplunkTrust
SplunkTrust

You probably don't want to hear this, but you should run it on *nix. I would recommend opening a support case

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...