Note - Above details was taken after restarting the splunkd service, as swap memory was completely utilized over a period of time. Kindly let guide us in overcoming this problem. In a month we are getting almost 20 alerts for this issue. Sometimes the swap memory becomes almost zero and kills the splunkd process. Problem - Most of the time we get an alert from Unix team stating that the splunkd process is consuming more CPU/Swap memory. HF is used to forward the data (syslog) to the 5 individual indexer instances and we have an F5 load balancer that is placed before the two HF servers to route the traffic. We have two heavy forwarder/syslog instances running in the same server.
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |