Hello,
I do not have access to the OS machines of the Splunk but I suspect the CPU bottleneck because my alert jobs are having 3 min lag between scheduling and dispatching. I would like to investigate it further.
Is there any way to query the internal index for the CPU utilization of the SH or indexer?
Kind Regards,
Kamil
↧