Hello Splunk Community, I am facing an issue and would appreciate your guidance. Currently, I am sending threats (Notable Events) to Splunk SOAR using the Splunk App for SOAR Export. Previously, the threats were delivered to SOAR almost instantly (near real-time) without any noticeable delay. However, after installing Splunk Enterprise Security version 8.1, I started to experience a delay of approximately 10–15 minutes before the threats reach SOAR. Observations: System resources are sufficient: vCPU: 90 RAM: 60 GB After installing ES, there is a significant increase in CPU utilization, with multiple splunkd and python3.9 processes consuming high CPU, for example: %CPU %MEM COMMAND
165.0 4.3 splunkd
114.9 0.3 splunkd
72.6 0.2 splunkd
66.7 0.2 splunkd
66.0 0.2 splunkd
24.4 0.0 python3.9 Connectivity between Splunk and SOAR is healthy, with no connection errors. After restarting the Splunk platform, threats are sent quickly with no delay. After some uptime, the delay returns again. No configuration changes were made on the SOAR side. The only change in the environment was installing Splunk Enterprise Security 8.1. My questions: Is this behavior known in ES 8.1? Could any settings related to: Adaptive Response Notable Events pipeline Correlation Search Scheduler cause this delay? Which logs or metrics would you recommend checking to identify the root cause? Any guidance or similar experiences would be greatly appreciated. Thank you in advance
... View more