<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Hitting limit: maximum number of concurrent auto-summarization - with 0 events and idle CPU in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Hitting-limit-maximum-number-of-concurrent-auto-summarization/m-p/660955#M27582</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/255865"&gt;@MichalG1&lt;/a&gt;, ES requires 16 CPU, 32 GB Memory (&lt;A href="https://docs.splunk.com/Documentation/ES/7.2.0/Install/DeploymentPlanning)" target="_blank"&gt;https://docs.splunk.com/Documentation/ES/7.2.0/Install/DeploymentPlanning)&lt;/A&gt;. However, if the ask is to update&amp;nbsp;max_searches_per_cpu and&amp;nbsp;base_max_searches on pre-prod environment (and not prod), you can go ahead and try doing that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would also suggest disabling the Data Model Accelerations, as well as, reviewing the correlation searches which are enabled by default - because the issue seems to be with the scheduler getting a lot of searches to execute at any given time (and not resources issue). You can also review the alert actions and corn schedules, through this search (and stagger cron schedule if needed) -&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rest splunk_server=local count=0 /servicesNS/-/SplunkEnterpriseSecuritySuite/saved/searches
| where match('action.correlationsearch.enabled', "1|[Tt]|[Tt][Rr][Uu][Ee]")
| where disabled=0
| eval actions=split(actions, ",")
| rename title as "Correlation Search", cron_schedule as "Cron Schedule" "dispatch.earliest_time" as "Earliest Time" dispatch.latest_time as "Latest Time" actions as "Actions"
| table "Correlation Search" "Cron Schedule" "Earliest Time" "Latest Time" "Actions"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Please accept the solution and hit Karma, if this helps!&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 17 Oct 2023 02:25:34 GMT</pubDate>
    <dc:creator>meetmshah</dc:creator>
    <dc:date>2023-10-17T02:25:34Z</dc:date>
    <item>
      <title>Hitting limit: maximum number of concurrent auto-summarization - with 0 events and idle CPU</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Hitting-limit-maximum-number-of-concurrent-auto-summarization/m-p/660793#M27580</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;&lt;P&gt;Pre staging environment (not production), a single server with 12 CPU + 24 GB or memory + raid0 nvme (2.5GB/s write, 5GB/s read). All in one deployment (SH + indexer). CPU cores with HT on dedicated server (6 cores with HT = 12 CPU -&amp;gt; but not used by any other VM).&lt;/P&gt;&lt;P&gt;Splunk 9.1.1 and ES 7.1.1. Fresh install. NO data ingested (0 events in most of the indexes including main, notable, risk etc...) - so basically no data yet to be processed.&lt;/P&gt;&lt;P&gt;Default ES configuration, i have not yet tuned any correlation searches etc. Defaults. And already performance problems:&lt;/P&gt;&lt;P&gt;1. MC Scheduler Activity Instance showing 22% skipped.&lt;/P&gt;&lt;P&gt;2. ESX reporting minimal CPU usage (the same with memory):&lt;/P&gt;&lt;P&gt;3. MC showing more details, many different Accelerated DM tasks are skipped, all the time:&lt;/P&gt;&lt;P&gt;Questions:&lt;/P&gt;&lt;P&gt;1. obviously the first recommendation would be to disable many of correlation searches/accelerated DMs, but that not what i would like do because the aim is to test complete ES functionality (by generating a small number of different types of events). Why do i have those problems in a first place ?&lt;/P&gt;&lt;P&gt;I can see that all the tasks are very short, finishes in 1 second, just few takes several seconds. And that is expected since i have 0 events everywhere and i do always expect to have a small number of events on this test deployment. What should i do to tune it and make sure there are no problems with skipped jobs ?&lt;/P&gt;&lt;P&gt;Shall i increase&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;max_searches_per_cpu &lt;/PRE&gt;&lt;PRE&gt;base_max_searches&amp;nbsp;&lt;/PRE&gt;&lt;P&gt;Any other ideas ? Overall that seems weird,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-10-15 at 19.05.32.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/27583i8219230A4C34A97D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-10-15 at 19.05.32.png" alt="Screenshot 2023-10-15 at 19.05.32.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-10-15 at 19.02.57.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/27582i549C3FC5AFD142DE/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-10-15 at 19.02.57.png" alt="Screenshot 2023-10-15 at 19.02.57.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-10-15 at 19.00.46.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/27581iFA726314E1DC7396/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-10-15 at 19.00.46.png" alt="Screenshot 2023-10-15 at 19.00.46.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Oct 2023 17:12:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Hitting-limit-maximum-number-of-concurrent-auto-summarization/m-p/660793#M27580</guid>
      <dc:creator>MichalG1</dc:creator>
      <dc:date>2023-10-15T17:12:31Z</dc:date>
    </item>
    <item>
      <title>Re: Hitting limit: maximum number of concurrent auto-summarization - with 0 events and idle CPU</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Hitting-limit-maximum-number-of-concurrent-auto-summarization/m-p/660955#M27582</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/255865"&gt;@MichalG1&lt;/a&gt;, ES requires 16 CPU, 32 GB Memory (&lt;A href="https://docs.splunk.com/Documentation/ES/7.2.0/Install/DeploymentPlanning)" target="_blank"&gt;https://docs.splunk.com/Documentation/ES/7.2.0/Install/DeploymentPlanning)&lt;/A&gt;. However, if the ask is to update&amp;nbsp;max_searches_per_cpu and&amp;nbsp;base_max_searches on pre-prod environment (and not prod), you can go ahead and try doing that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would also suggest disabling the Data Model Accelerations, as well as, reviewing the correlation searches which are enabled by default - because the issue seems to be with the scheduler getting a lot of searches to execute at any given time (and not resources issue). You can also review the alert actions and corn schedules, through this search (and stagger cron schedule if needed) -&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rest splunk_server=local count=0 /servicesNS/-/SplunkEnterpriseSecuritySuite/saved/searches
| where match('action.correlationsearch.enabled', "1|[Tt]|[Tt][Rr][Uu][Ee]")
| where disabled=0
| eval actions=split(actions, ",")
| rename title as "Correlation Search", cron_schedule as "Cron Schedule" "dispatch.earliest_time" as "Earliest Time" dispatch.latest_time as "Latest Time" actions as "Actions"
| table "Correlation Search" "Cron Schedule" "Earliest Time" "Latest Time" "Actions"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Please accept the solution and hit Karma, if this helps!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 02:25:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Hitting-limit-maximum-number-of-concurrent-auto-summarization/m-p/660955#M27582</guid>
      <dc:creator>meetmshah</dc:creator>
      <dc:date>2023-10-17T02:25:34Z</dc:date>
    </item>
  </channel>
</rss>

