|
I am using the light forwarder on AIX and running into high CPU usage (80-90% of a CPU). We tracked it down to using ellipse in the monitor line in inputs.conf. (even a "*" uses too much CPU). We are using the ellipse so that we can deploy the same inputs.conf to several machines, each with a different directory path. If we tighten it down to a single directory/file, things run great. My question is: Is there any way to have splunk traverse the directory tree less often (once a day or even less frequent), but still read files it already knows about in near real time? I did not see anything in the doc about a setting like that. |