Poor Performance When Running Splunk Enterprise on RHEL with Transparent Huge Pages Enabled
Issue
- Splunk Enterprise system (indexer) performance degraded significantly after upgrading from RHEL 5 to RHEL 6.
- Splunk Enterprise very high load. Iostat seems to indicate system is waiting on I/O with low disk utilization and low over all utilization.
- Splunk process (search engine) starts, load average spikes significantly, and %sys increases. Don't seem to be sending/waiting on IO.
Environment
- Red Hat Enterprise Linux 5
- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.