Security

Concurrent searches in Splunk (System wide & user specific)

splunker12er
Motivator

I do have Search head with 16 cores & 2Gb RAM Memory , using Splunk 5.x

As , per the calculation for Concurrent search , My system wide Concurrent search is 22

max_hist_searches =  max_searches_per_cpu x number_of_cpus + base_max_searches
max_hist_searches = 1 x 16 + 6 => 16 + 6 => 22

22 is the maximum number of concurrent search that my search hear can handle.

I do see for 'admin' role the values are as below :

Limit concurrent search jobs = 50
Limit concurrent real-time search jobs =100

These values are present by default in the Splunk web under authrorize.conf file.

How does the maximum concurrent search jobs limit can be 50 , when the system wide range itself 22 ?

Also , if I do specify the a count greater than the system wide limit does Splunk overrides the value within the allowed range ?

In this case , how do other users are affected , when 'admin' user takes the full control when he has maximum concurrent search limit ?

I am confused in this. Please advise on how to limit the users on concurrent search , considering the system wide limit.

0 Karma

ecambra_splunk
Splunk Employee
Splunk Employee

Most of the default settings are helpful for understanding how role administration works, but should be customized for your environment. You will never be able to exceed the hardware limits, but hitting the limit will result in queued searches and poor user experience.

Other things to watch out for are a high volume of real-time searches, scheduled searches and dashboards running inline searches. All of these are competing for the same pool of resources. So, if you have admin/power users who are creating and consuming without consideration for search-head resources it could cause issues for other users.

If you are able to, I would recommend installing the S.O.S. app. It's great for troubleshooting resource issues.
http://apps.splunk.com/app/748/

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...