<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What are the proper user quotas to protect our indexers? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-proper-user-quotas-to-protect-our-indexers/m-p/490019#M83762</link>
    <description>&lt;P&gt;A few things you can look at:&lt;BR /&gt;
You can modify times.conf and verify users are not searching All time by default&lt;BR /&gt;
 &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Admin/Timesconf"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Admin/Timesconf&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/79547/disable-all-time.html"&gt;https://answers.splunk.com/answers/79547/disable-all-time.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Force users to specify indexes in their queries by verifying that "Indexes searched by default" for the role assigned to the users is NOT set to "All non-internal indexes"&lt;/P&gt;

&lt;P&gt;Verify that data is being distributed equally to indexers (more or less) otherwise the workload won't be evenly distributed and you'll be waiting longer for the query to complete if one indexer is doing most of the work. splunk_server is the field name representing the indexer that is hosting/serving the data.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;your base query | top 100 splunk_server
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Thu, 26 Sep 2019 03:55:01 GMT</pubDate>
    <dc:creator>bandit</dc:creator>
    <dc:date>2019-09-26T03:55:01Z</dc:date>
    <item>
      <title>What are the proper user quotas to protect our indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-proper-user-quotas-to-protect-our-indexers/m-p/490016#M83759</link>
      <description>&lt;P&gt;Yesterday, one indexer got crashed due to a very badly developed dashboard - it instantly  consumed all the memory of the indexer.&lt;/P&gt;

&lt;P&gt;Which quotas should we place in order to prevent such cases?&lt;/P&gt;

&lt;P&gt;Btw, it does seem that this particular indexer ran all or most of the queries of this dashboard, which is weird.  &lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/7732i44228E0DC2827D1D/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2019 15:27:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-proper-user-quotas-to-protect-our-indexers/m-p/490016#M83759</guid>
      <dc:creator>danielbb</dc:creator>
      <dc:date>2019-09-25T15:27:21Z</dc:date>
    </item>
    <item>
      <title>Re: What are the proper user quotas to protect our indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-proper-user-quotas-to-protect-our-indexers/m-p/490017#M83760</link>
      <description>&lt;P&gt;Have a look at this:&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.1/Search/Limitsearchprocessmemoryusage"&gt;https://docs.splunk.com/Documentation/Splunk/7.3.1/Search/Limitsearchprocessmemoryusage&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2019 18:40:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-proper-user-quotas-to-protect-our-indexers/m-p/490017#M83760</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2019-09-25T18:40:23Z</dc:date>
    </item>
    <item>
      <title>Re: What are the proper user quotas to protect our indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-proper-user-quotas-to-protect-our-indexers/m-p/490018#M83761</link>
      <description>&lt;P&gt;That's great. Btw, what's the default max memory allocation per a search query?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2019 20:58:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-proper-user-quotas-to-protect-our-indexers/m-p/490018#M83761</guid>
      <dc:creator>danielbb</dc:creator>
      <dc:date>2019-09-25T20:58:54Z</dc:date>
    </item>
    <item>
      <title>Re: What are the proper user quotas to protect our indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-proper-user-quotas-to-protect-our-indexers/m-p/490019#M83762</link>
      <description>&lt;P&gt;A few things you can look at:&lt;BR /&gt;
You can modify times.conf and verify users are not searching All time by default&lt;BR /&gt;
 &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Admin/Timesconf"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Admin/Timesconf&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/79547/disable-all-time.html"&gt;https://answers.splunk.com/answers/79547/disable-all-time.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Force users to specify indexes in their queries by verifying that "Indexes searched by default" for the role assigned to the users is NOT set to "All non-internal indexes"&lt;/P&gt;

&lt;P&gt;Verify that data is being distributed equally to indexers (more or less) otherwise the workload won't be evenly distributed and you'll be waiting longer for the query to complete if one indexer is doing most of the work. splunk_server is the field name representing the indexer that is hosting/serving the data.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;your base query | top 100 splunk_server
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 26 Sep 2019 03:55:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-proper-user-quotas-to-protect-our-indexers/m-p/490019#M83762</guid>
      <dc:creator>bandit</dc:creator>
      <dc:date>2019-09-26T03:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: What are the proper user quotas to protect our indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-proper-user-quotas-to-protect-our-indexers/m-p/490020#M83763</link>
      <description>&lt;P&gt;@somesoni2 - I see these values on the indexers -&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;$SPLUNK_HOME/etc/system/default/limits.conf - enable_memory_tracker = false
$SPLUNK_HOME/etc/system/default/limits.conf - search_process_memory_usage_percentage_threshold = 25
$SPLUNK_HOME/etc/system/default/limits.conf - search_process_memory_usage_threshold = 4000
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Should we change these values on the indexers and on the SHs as well?&lt;/P&gt;</description>
      <pubDate>Fri, 27 Dec 2019 16:12:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-proper-user-quotas-to-protect-our-indexers/m-p/490020#M83763</guid>
      <dc:creator>danielbb</dc:creator>
      <dc:date>2019-12-27T16:12:20Z</dc:date>
    </item>
  </channel>
</rss>

