The total indexing throughput per indexer was reduced significantly after upgrading to 5.0 or 5.1 from 4.3.x. Splunk is spending considerable amounts of CPU time on service_maxSizes. Due to this issue, forwarder connections are being refused by the indexers. What is going on here?
↧