Have you checked crash log in splunk log directory??
Check your ulimit as well, on Linux default ulimit is 1024. And splunk suggest alteast 8192 for user from splunkd is running.
... View more
Hi,
Many apps have scheduled searches, their views and macros. So if you will install app, it will schedule searches(if app have) and if app have separate indexes and app will write data in those indexes.
Yes, there is a performance consideration, please check
http://docs.splunk.com/Documentation/Splunk/latest/Capacity/HowSplunkappsaffectSplunkEnterpriseperformance
... View more