Alerting

Splunk is showing high CPU load on Linux Server

4uramana4u
Explorer

Hello Splunk Experts,

I have an issue with measuring the CPU load in a Linux box. 

With the below query, I am getting a high CPU usage when there were no activities running on Linux Server.

Actually, the server status is pretty much an Idea most of the time and it is being used as a backup server.

cpu_load = 100 - PercentIdleTime;   

eval cpu_load = 100 - PercentIdleTime | stats avg(cpu_load) as "CPUUsage" by host | eval "CPUUsage"=round('CPUUsage', 2) | where CPUUsage>90

 

 

Labels (1)
Tags (1)
0 Karma

Pikta
Explorer

Hi,  @4uramana4u 
Can you write your Linux machine parameters? 
Maybe the answer in your question is here:

Splunk hardware requirements
The following are the minimum and recommended hardware requirements for running Splunk Light.

Platform : Non-Windows platforms 

Minimum supported hardware: 1x1.4 GHz CPU, 1 GB RAM

Recommended hardware :  2x six-core, 2+ GHz CPU, 12 GB RAM, Redundant Array of Independent Disks (RAID) 0 or 1+0, with a 64 bit OS installed.

0 Karma

4uramana4u
Explorer

@Pikta 

Thanks for the reply. 

The intended server is actually a Database server managing the production data and we want the CPU usage to be monitored by Splunk.

In terms of hardware, it is well equipped and it has nearly 1 million DB transactions per day. 

 

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...

Enterprise Security Content Update (ESCU) | New Releases

In April, the Splunk Threat Research Team had 2 releases of new security content via the Enterprise Security ...