Using redhat 6, I've noticed that my Splunk instance has searches that are consuming large amounts of CPU and I am experiencing quite a bit of latency. Has anyone else seen this? Is there something I can do to easily mitigate this problem?
I'm suspecting Transparent Huge Pages (THP) is enabled, as of RH 6 I believe this was enabled by default to deal with Oracle Databases or Big DATA.
for more information. https://blogs.oracle.com/linux/entry/performance_issues_with_transparent_huge
To disable it:
/sys/kernel/mm/transparent_hugepage/enabled = never
View solution in original post
We will have an official statement on this in the Splunk documentation shortly. I'll update this comment with appropriate URLs at the proper time.