Splunk Search

Search is queued: The maximum number of historical concurrent system-wide searches has been reached. current=11 maximum=10 Search not executed!

wudu0517
New Member

I'm in search of the above tips on how to solve?

Tags (1)
0 Karma

wudu0517
New Member

Splunk 5.0.1 ,

limit.conf
[subsearch]
maxout=10000
maxtime = 1800

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

What version of Splunk? Did you change anything in limits.conf?

0 Karma

wudu0517
New Member

Splunk Search Head 2 CPU 8 core, 8G memory

0 Karma

fengjie
New Member

I try, thank you very much!

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

How many CPU and How Much RAM does your Search Head have?

0 Karma

jtrucks
Splunk Employee
Splunk Employee

Go to Manage -> Access controls -> Roles. I suspect you are a Power user (or other role with similar job limit settings), so either create a new role or edit Power to increase "Limit concurrent search jobs" to a higher number.

--
Jesse Trucks
Minister of Magic

linu1988
Champion

It depends on the role of the user and maximum number of searches allowed to that use. You can see them in access control->roles->Role_Name if you are an ADMIN. There you can modify the number of searched availed to the role, which the user belong to. Thanks.

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...