Splunk Search

Why is the Memory Tracker not working as expected?

dvg06
Path Finder

Hi Splunkers,

We have set search_process_memory_usage_threshold to 3GB, but noticed that searches are terminated when the usage reaches much higher values, example below.
Is this expected behaviour, or is there any other parameter to be enabled make it work better?

09-13-2018 10:59:00.013 +1000 WARN  SearchProcessMemoryTracker - Dispatch Command: The search processs with sid=XXXX was forcefully terminated because its physical memory usage (5626.160000 MB) has exceeded the 'search_process_memory_usage_threshold' (3000.000000 MB) setting in limits.conf.
0 Karma
1 Solution

traxxasbreaker
Communicator

Most likely the search's memory passed the threshold very quickly in between memory tracker doing its periodic checks. At a glance of the available limits.conf settings, I don't see anything that would let you tune the polling interval of memory tracker.

View solution in original post

0 Karma

dvg06
Path Finder

Thanks traxxasbreaker

0 Karma

traxxasbreaker
Communicator

Most likely the search's memory passed the threshold very quickly in between memory tracker doing its periodic checks. At a glance of the available limits.conf settings, I don't see anything that would let you tune the polling interval of memory tracker.

0 Karma

dvg06
Path Finder

thanks @traxxasbreaker.

Do we get an option to configure this period for checks?

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...