Splunk® Enterprise

Workload Management

Acrobat logo Download manual as PDF


Splunk Enterprise version 8.2 is no longer supported as of September 30, 2023. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk® Enterprise. For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

System requirements

This page lists the requirements for Workload Management.

Splunk Enterprise version requirements

Workload management requires Splunk Enterprise version 7.2.0 or higher.

The following workload management features are available in the specified Splunk Enterprise version:

  • Automated Linux preflight checks requires version 7.2.2. or higher.
  • Workload categories (search, ingest, and misc) requires version 7.3.0 or higher.
  • Workload rules for workload pool monitoring and actions requires version 8.0.0 or higher.
  • Admission rules for pre-filtering searches requires version 8.1.0 or higher.

Linux operating system requirements

Workload management for Splunk Enterprise is supported on Linux operating systems only.

Linux kernel

Workload management requires Linux kernel version 2.6.25 or higher. For information on currently supported and deprecated Linux kernel versions for Splunk Enterprise, see Supported operating systems in the Installation Manual.

Supported Linux distributions

Splunk Enterprise supports workload management on these Linux distributions:

  • RHEL 6, 7, 8, and 9
  • CentOS 6, 7, and 8
  • Ubuntu 16.04 LTS and higher
  • SUSE 11 and 12

Supported cgroups version

Workload management supports Linux cgroups v1 only.

Workload management is not compatible with Linux cgroups v2. If your Linux system has been upgraded to a version that runs cgroups v2 by default, you must revert your system to cgroups v1 to use Workload Management in Splunk Enterprise.

Before you can configure and enable workload management in Splunk Enterprise, you must set up the underlying Linux operating system to allow splunkd to manage cgroups. See Set up Linux for workload management.

Systemd version

Workload management requires systemd version 219 or higher.

Systemd is not a mandatory requirement, but if systemd is running on your Linux instance, it must be version 219 or higher.

Last modified on 24 January, 2024
PREVIOUS
How workload management works
  NEXT
Set up Linux for workload management

This documentation applies to the following versions of Splunk® Enterprise: 8.1.0, 8.1.1, 8.1.2, 8.1.3, 8.1.4, 8.1.5, 8.1.6, 8.1.7, 8.1.8, 8.1.9, 8.1.10, 8.1.11, 8.1.12, 8.1.13, 8.1.14, 8.2.0, 8.2.1, 8.2.2, 8.2.3, 8.2.4, 8.2.5, 8.2.6, 8.2.7, 8.2.8, 8.2.9, 8.2.10, 8.2.11, 8.2.12


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters