Hi all,
I'm deploying splunk 4 as a lightweight forwarder on our production servers. I've set it up to monitor WMI about every 10 seconds as well as our application logs. If I move the logs away, I get 100% usage for about half a second, then very little. If there are a large amount of logs in the monitored when I start slunk the first time, the indexing and forwarding of the data uses all my app server's CPU. Is there a way I can limit the CPU usage of the splunkd service on windows server 2003?
Thanks,
Todd