Monitoring Splunk

number of splunkd processes rising

ctripod
Explorer

I have a linux host running 6.0.2 and I notice that the number of splunkd rising on one of my indexers. When the processes get above 100+ splunkd processes everything starts to suffer. Has anyone seen this? Under what circumstances does splunk start to spawn more processes?

Tags (1)
0 Karma

MuS
SplunkTrust
SplunkTrust

Hi ctripod,

normally there are three kind of splunkd processes around which can be shown by using the $SPLUNK_HOME/bin/splunk status command. You will get a list of PID's for the main Splunk process, Splunk Web process and Splunk helper processes.
Those helper processes are mainly your searches, so if you see the amount of helper processes raising means you run more searches. Form the command output you can use the PID and check what searches are running or you use the S.o.S app and check your searches from there.

hope this helps ...

cheers, MuS

Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...