I deployed splunk universal forwarder 9.1.1 on Linux servers which are running on VPC VSI in IBM Cloud. Some servers are RHEL7 others are RHEL8. These servers send logs to Heavy Forwarder server. After deployment, the memory usage was coming to high on each server and one of the server went down because of memory leak. CPU usage is also high as expected when the splunk process is running. For example, one of the server's CPU usage increased 30% and consumed 5.7GB memory out of 14GB after the splunk process up. How can I reduce the resource usage?
... View more