Splunk Search

Solaris *nix Splunkd high load average

fizwit
Explorer

Using the Splunk App for *nix on Solair. splunkd has a very high load average. In 15 seconds it did an lstat of 6659 files. Not sure why so many files are being monitored.

Tags (4)
0 Karma

fizwit
Explorer

problem solved:

modify: $SPLUNK_HOME/etc/apps/unix/local/inputs.conf
[monitor:///home/.../.bash_history]
disabled = 1

Splunk app for *NIX was spending all its time stating files in /home. (30% CPU) removing /home from monitor solved the problem.

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...