@swmishra_splunk hi, we are seeing the same "too many tsidx files" on our DMC - for indexers that are overloaded on CPU, which half is splunk-optimizes. I've seen up to 164 tsidx files in one bucket and our optimize settings are default. Version 8.2.2.1. These are on hardware servers with 16 cores. maxConcurrentOptimizes = 6
maxRunningProcessGroups = 8
maxRunningProcessGroupsLowPriority = 1
processTrackerServiceInterval = 1 Our main issue is that we're running into ingest lag due to CPU being saturated by the optimize processes, along with search/ingest. I was suggested the we try setting the processTrackerServiceInterval to 60 to allow ingest lag to catch up. Will that help us there? I will try matching the other settings you recommend as well, but wanted to test 1 thing at a time.
... View more