I had to “End Process” when it had used 1.2G of my RAM.
I am running version 5.0 ...
Something configured incorrectly?
I know there's a known bug in 5.0 where the process splunkd.exe eats ram if receiving large amounts of UDP traffic.
"We have determined that in Splunk 5.0, active UDP inputs cause the main splunkd process to leak memory. The rate of this memory leak appears to be proportional to the rate of data that is being received on the UDP input(s). For that reason, it is possible for a very active UDP input to cause splunkd to eventually exhaust all available memory on the host.
The bug that references this behavior is SPL-58075 and has been added to the list of known issues for Splunk 5.0.
We are actively working towards the release of a fix to this issue in the next few days."