Skip to main content

Cribl Stream Suppress Function Memory Exhaustion from High-Cardinality Keys

  • October 7, 2026
  • 0 replies
  • 3 views

Jessica Bracken

Symptom

  • Cribl Stream Worker Processes consume most or all available memory after Suppress functions are enabled or their cache settings increase.
  • Worker Processes restart, become unresponsive, or worker nodes become unavailable after memory pressure or an operating-system out-of-memory event.

Environment

  • Cribl Stream
  • Pipeline Suppress functions
  • Distributed deployment with multiple Worker Processes

Resolution

  1. Review each Suppress function’s filter, key expression, suppression period, cache size limit, and cleanup settings.

    1. Estimate the distinct key count for each key expression during one suppression period.

    2. Identify high-cardinality keys, such as source or destination fields with many unique values.

      1. Reduce the key cardinality when the suppression requirement allows it.

    3. Keep the default cache size limit unless required

      1. Increase the cache size incrementally in a controlled test when a larger cache is required.

  2. Disable duplicate Suppress functions that run simultaneously in replicated development and production packs.

  3. Verify that the Worker Process count and host memory provide sufficient headroom for all stateful functions. Default limit per worker process is 2048 but you need to confirm node has enough total memory to meet that allocation for number of worker processes on the node.

Cause

This can be caused by:

  • High-cardinality key expressions that create many in-memory suppression entries.
  • Multiple Suppress functions or duplicated packs that multiply in-memory state.
  • Suppress state being maintained independently by each Worker Process and not being accounted for.
  • Increasing cache limits without measuring cardinality, process count, and host-memory headroom.

Additional Information

  • The Suppress Function documentation describes cache size limits, suppression-period timeouts, and cache cleanup settings.
  • The Sizing and Scaling documentation explains per-Worker-Process heap memory and how Suppress memory usage increases with key cardinality.
  • A larger cache does not provide cross-Worker-Process suppression. A shared-state design like Redis is required when suppression must be coordinated across processes.