This page lists the requirements for Workload Management.
Splunk Enterprise version requirements
Workload management requires Splunk Enterprise version 7.2.0 or higher.
The following workload management features are available in the specified Splunk Enterprise version:
- Automated Linux preflight checks requires version 7.2.2. or higher.
- Workload categories (search, ingest, and misc) requires version 7.3.0 or higher.
- Workload rules for workload pool monitoring and actions requires version 8.0.0 or higher.
- Admission rules for pre-filtering searches requires version 8.1.0 or higher.
Linux operating system requirements
Workload management for Splunk Enterprise is currently supported on Linux operating systems only.
Workload management requires Linux kernel version 2.6.25 or higher. For information on currently supported and deprecated Linux kernel versions for Splunk Enterprise, see Supported operating systems in the Installation Manual.
Supported Linux distributions
Splunk Enterprise supports workload management on these Linux distributions:
- RHEL 6, 7, 8, and 9
- CentOS 6, 7, and 8
- Ubuntu 16.04 LTS and higher
- SUSE 11 and 12
Workload management requires cgroups version 1.0.
Before you can configure and enable workload management in Splunk Enterprise, you must set up the underlying Linux operating system to allow splunkd to manage cgroups. See Set up Linux for workload management.
Workload management requires systemd version 219 or higher.
Systemd is not a mandatory requirement, but if systemd is running on your Linux instance, it must be version 219 or higher.
How workload management works
Set up Linux for workload management
This documentation applies to the following versions of Splunk® Enterprise: 8.1.0, 8.1.1, 8.1.2, 8.1.3, 8.1.4, 8.1.5, 8.1.6, 8.1.7, 8.1.8, 8.1.9, 8.1.10, 8.1.11, 8.1.12, 8.2.0, 8.2.1, 8.2.2, 8.2.3, 8.2.4, 8.2.5, 8.2.6, 8.2.7, 8.2.8, 8.2.9, 9.0.0, 9.0.1, 9.0.2