Hello, splunker.
I have about 50 savedsearch.
It's schedule is executed once every 30 minutes and my workstation have 4 core.
So I set it as follows.
[search]
base_max_searches = 24
max_searches_per_cpu = 4
[scheduler]
max_searches_perc = 200
however, my splunk so slow.
I can't access splunk and putty shell
why?
I am splunk novice.
please help me.
thank you.
Those settings are way too high for your system.
Try these instead:
[search]
base_max_searches = 6
max_searches_per_cpu = 2
[scheduler]
max_searches_perc = 80
Also make sure that your scheduled searches are not running "all-time" queries, e.g.
Those settings are way too high for your system.
Try these instead:
[search]
base_max_searches = 6
max_searches_per_cpu = 2
[scheduler]
max_searches_perc = 80
Also make sure that your scheduled searches are not running "all-time" queries, e.g.
ty your answer but, i will upgrade my server. it is 8 core. how do i set my server?
I would suggest testing the parameters I supplied. I think the most important change in your config is the max_searches_perc, which you previously had/have set to 200%. Try the suggested settings then evaluate how your system performs.
thank you. It helped me a lot.