<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: High RAM usage on Splunk Indexer in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/High-RAM-usage-on-Splunk-Indexer/m-p/157189#M7631</link>
    <description>&lt;P&gt;Thank-you so much for the quick reply and excellent suggestions. I will educate my users, would you be able to supply me with a sample search that I can use to determine long running searches please.&lt;/P&gt;</description>
    <pubDate>Wed, 27 Nov 2013 16:23:47 GMT</pubDate>
    <dc:creator>rdelmark</dc:creator>
    <dc:date>2013-11-27T16:23:47Z</dc:date>
    <item>
      <title>High RAM usage on Splunk Indexer</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/High-RAM-usage-on-Splunk-Indexer/m-p/157187#M7629</link>
      <description>&lt;P&gt;At times I have seen users run searches like index=* and let it run, (this user only has restricted access to 3 indexes of our 35 total), this search take up to 7GB of RAM on the Splunk Indexer.&lt;/P&gt;

&lt;P&gt;How can we control this, we have 100 Splunk users. In the past some users have pushed the Splunk indexer RAM usage up to 99% and froze the Splunk indexer.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2013 21:46:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/High-RAM-usage-on-Splunk-Indexer/m-p/157187#M7629</guid>
      <dc:creator>rdelmark</dc:creator>
      <dc:date>2013-11-26T21:46:00Z</dc:date>
    </item>
    <item>
      <title>Re: High RAM usage on Splunk Indexer</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/High-RAM-usage-on-Splunk-Indexer/m-p/157188#M7630</link>
      <description>&lt;P&gt;Although &lt;CODE&gt;index=*&lt;/CODE&gt;  is a pretty bad search, it is also a legitimate one, so you can't really use any search filters. There are several things that you can do here but none of them will pay better than &lt;STRONG&gt;educating your users&lt;/STRONG&gt;. Other solutions include, (1) changing the default Time Range Picker from All Time to Last 60min or Last 24hr, and/or (2) getting alerted on long running searches and taking corresponding action to kill the offending process. &lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2013 00:16:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/High-RAM-usage-on-Splunk-Indexer/m-p/157188#M7630</guid>
      <dc:creator>_d_</dc:creator>
      <dc:date>2013-11-27T00:16:56Z</dc:date>
    </item>
    <item>
      <title>Re: High RAM usage on Splunk Indexer</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/High-RAM-usage-on-Splunk-Indexer/m-p/157189#M7631</link>
      <description>&lt;P&gt;Thank-you so much for the quick reply and excellent suggestions. I will educate my users, would you be able to supply me with a sample search that I can use to determine long running searches please.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2013 16:23:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/High-RAM-usage-on-Splunk-Indexer/m-p/157189#M7631</guid>
      <dc:creator>rdelmark</dc:creator>
      <dc:date>2013-11-27T16:23:47Z</dc:date>
    </item>
    <item>
      <title>Re: High RAM usage on Splunk Indexer</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/High-RAM-usage-on-Splunk-Indexer/m-p/157190#M7632</link>
      <description>&lt;P&gt;Thank-you so much for the quick reply and excellent suggestions. I will educate my users, would you be able to supply me with a sample search that I can use to determine long running searches please.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2013 16:24:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/High-RAM-usage-on-Splunk-Indexer/m-p/157190#M7632</guid>
      <dc:creator>rdelmark</dc:creator>
      <dc:date>2013-11-27T16:24:08Z</dc:date>
    </item>
    <item>
      <title>Re: High RAM usage on Splunk Indexer</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/High-RAM-usage-on-Splunk-Indexer/m-p/157191#M7633</link>
      <description>&lt;P&gt;There are several ways to get that information. But first I would use the _audit index to identify users with historically long running searches and inform them appropriately. Next, to determine &lt;EM&gt;currently&lt;/EM&gt; long running searches I would use the following search &lt;CODE&gt;| rest /services/search/jobs | search dispatchState=RUNNING | table dispatchState runDuration title&lt;/CODE&gt; and check the &lt;CODE&gt;runDuration&lt;/CODE&gt; field for excessive values - whatever that means in your context.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2013 16:37:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/High-RAM-usage-on-Splunk-Indexer/m-p/157191#M7633</guid>
      <dc:creator>_d_</dc:creator>
      <dc:date>2013-11-27T16:37:57Z</dc:date>
    </item>
  </channel>
</rss>

