Security

Concurrent searches in Splunk (System wide & user specific)

splunker12er
Motivator

I do have Search head with 16 cores & 2Gb RAM Memory , using Splunk 5.x

As , per the calculation for Concurrent search , My system wide Concurrent search is 22

max_hist_searches =  max_searches_per_cpu x number_of_cpus + base_max_searches
max_hist_searches = 1 x 16 + 6 => 16 + 6 => 22

22 is the maximum number of concurrent search that my search hear can handle.

I do see for 'admin' role the values are as below :

Limit concurrent search jobs = 50
Limit concurrent real-time search jobs =100

These values are present by default in the Splunk web under authrorize.conf file.

How does the maximum concurrent search jobs limit can be 50 , when the system wide range itself 22 ?

Also , if I do specify the a count greater than the system wide limit does Splunk overrides the value within the allowed range ?

In this case , how do other users are affected , when 'admin' user takes the full control when he has maximum concurrent search limit ?

I am confused in this. Please advise on how to limit the users on concurrent search , considering the system wide limit.

0 Karma

ecambra_splunk
Splunk Employee
Splunk Employee

Most of the default settings are helpful for understanding how role administration works, but should be customized for your environment. You will never be able to exceed the hardware limits, but hitting the limit will result in queued searches and poor user experience.

Other things to watch out for are a high volume of real-time searches, scheduled searches and dashboards running inline searches. All of these are competing for the same pool of resources. So, if you have admin/power users who are creating and consuming without consideration for search-head resources it could cause issues for other users.

If you are able to, I would recommend installing the S.O.S. app. It's great for troubleshooting resource issues.
http://apps.splunk.com/app/748/

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...