<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Restrict users to fire complex query | force kill the complex query ! in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Restrict-users-to-fire-complex-query-force-kill-the-complex/m-p/196214#M2037</link>
    <description>&lt;P&gt;Okay , After I upgrade Splunk to its latest version .. Suggest me what action i can handle ?&lt;/P&gt;</description>
    <pubDate>Tue, 07 Jan 2014 00:50:46 GMT</pubDate>
    <dc:creator>chimbudp</dc:creator>
    <dc:date>2014-01-07T00:50:46Z</dc:date>
    <item>
      <title>Restrict users to fire complex query | force kill the complex query !</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Restrict-users-to-fire-complex-query-force-kill-the-complex/m-p/196212#M2035</link>
      <description>&lt;P&gt;Background :&lt;BR /&gt;&lt;BR /&gt;
I am using Splunk verion 4.3.3 , having 4 indexer with 1 Search head and using the default configurations for limits.conf. &lt;BR /&gt;&lt;/P&gt;

&lt;P&gt;OS      : RHEL 6&lt;BR /&gt;&lt;BR /&gt;
Subnet : logging&lt;BR /&gt;&lt;BR /&gt;
HDD 1 : 40&lt;BR /&gt;&lt;BR /&gt;
HDD 2: 100&lt;BR /&gt;&lt;BR /&gt;
Memory : 16&lt;BR /&gt;&lt;BR /&gt;
CPU cores :4&lt;BR /&gt; &lt;/P&gt;

&lt;P&gt;By default settings my search head is capable of doing 4 concurrent searches. (as recommended by splunk)&lt;BR /&gt;
However often i am getting maximum historical search limit is reached. and this is quite annoying for my users.&lt;/P&gt;

&lt;P&gt;Suggest me a best idea to resolve this, (something from my readings , correct me if i am wrong below)&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Shall i tweak the default settings in
limits.conf .  How far this is
recommended to localize this
configuration file ?&lt;/LI&gt;
&lt;LI&gt;Shall i increase the no. of cores in
Search head's CPU ? &lt;/LI&gt;
&lt;LI&gt;Do i need to go for multiple search
heads ?&lt;/LI&gt;
&lt;/UL&gt;

&lt;HR /&gt;

&lt;P&gt;Can i try this ,&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;
restrict the Splunk users triggering a complex query | or a query which fetches very old data .&lt;BR /&gt;
Restrict features in TimeRange picker -remove  "All Time" selection&lt;/P&gt;

&lt;P&gt;However i wanted to limit the users from complex query. Is there any tricks ?&lt;BR /&gt;
or any way to force the search query to show limited data , even though long time range is selected ? &lt;/P&gt;

&lt;P&gt;Kindly advice.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;&lt;BR /&gt;
Chimbu&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2014 10:30:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Restrict-users-to-fire-complex-query-force-kill-the-complex/m-p/196212#M2035</guid>
      <dc:creator>chimbudp</dc:creator>
      <dc:date>2014-01-06T10:30:33Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to fire complex query | force kill the complex query !</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Restrict-users-to-fire-complex-query-force-kill-the-complex/m-p/196213#M2036</link>
      <description>&lt;P&gt;Version 4.3.3 is no longer supported. I suggest upgrading both Splunk and the number of cores you have. The hardware specification requirements are here: &lt;CODE&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.0.1/Installation/SystemRequirements#Recommended_hardware" target="test_blank"&gt;http://docs.splunk.com/Documentation/Splunk/6.0.1/Installation/SystemRequirements#Recommended_hardware&lt;/A&gt;&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2014 13:28:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Restrict-users-to-fire-complex-query-force-kill-the-complex/m-p/196213#M2036</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2014-01-06T13:28:15Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to fire complex query | force kill the complex query !</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Restrict-users-to-fire-complex-query-force-kill-the-complex/m-p/196214#M2037</link>
      <description>&lt;P&gt;Okay , After I upgrade Splunk to its latest version .. Suggest me what action i can handle ?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2014 00:50:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Restrict-users-to-fire-complex-query-force-kill-the-complex/m-p/196214#M2037</guid>
      <dc:creator>chimbudp</dc:creator>
      <dc:date>2014-01-07T00:50:46Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to fire complex query | force kill the complex query !</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Restrict-users-to-fire-complex-query-force-kill-the-complex/m-p/196215#M2038</link>
      <description>&lt;P&gt;The message shows up because of the limitation on the roles for concurrent searches. You can have savedsearch to avoid this, or the maximum concurrent searches needs to be altered&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2014 05:15:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Restrict-users-to-fire-complex-query-force-kill-the-complex/m-p/196215#M2038</guid>
      <dc:creator>linu1988</dc:creator>
      <dc:date>2014-01-07T05:15:59Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to fire complex query | force kill the complex query !</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Restrict-users-to-fire-complex-query-force-kill-the-complex/m-p/196216#M2039</link>
      <description>&lt;P&gt;I cant have savedseraches , since the searches are fired from some external componenets via REST API ...&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2014 05:31:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Restrict-users-to-fire-complex-query-force-kill-the-complex/m-p/196216#M2039</guid>
      <dc:creator>chimbudp</dc:creator>
      <dc:date>2014-01-07T05:31:44Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to fire complex query | force kill the complex query !</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Restrict-users-to-fire-complex-query-force-kill-the-complex/m-p/196217#M2040</link>
      <description>&lt;P&gt;Then it needs to be set particular to the role in  authorize.conf ,parameters like srchMaxTime,srchTimeWin,srchJobsQuota will help you restrict the users to have long queries. Regarding the complexity there are not many option if you don't have any static queries to allow them to.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2014 06:51:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Restrict-users-to-fire-complex-query-force-kill-the-complex/m-p/196217#M2040</guid>
      <dc:creator>linu1988</dc:creator>
      <dc:date>2014-01-07T06:51:04Z</dc:date>
    </item>
  </channel>
</rss>

