Hello,
Yesterday I noticed that there's a substantial lag in event indexing to the default index (main). When inspecting the processes on my machine, I noticed that a single splunkd process running at 100% cpu.
I tried to restart splunk several time, but splunk gets to 100% cpu immediately and stays there.
I've opened ticket at
[email protected], but no response till now.
After deleting the index and re-indexing things got back to normal.
24h later I'm encountering the same problem.
The machine splunk is running on has 16 CPUs, 8GB RAM. ~200MB of data is being indexed daily, and there's no significant search activity as well.
Will appreciate any help with that.
Oren.
... View more