<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic User level Concurrent search limits in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/User-level-Concurrent-search-limits/m-p/395995#M114965</link>
    <description>&lt;P&gt;Hi Everyone,&lt;BR /&gt;
On my system,  I have 2 CPU cores&lt;BR /&gt;
In $SPLUNKHOME/etc/system/local/limits.conf file I got below details,&lt;/P&gt;

&lt;P&gt;max_searches_per_cpu = 1&lt;/P&gt;

&lt;H1&gt;the base number of concurrent searches&lt;/H1&gt;

&lt;P&gt;base_max_searches = 6&lt;/P&gt;

&lt;H1&gt;max real-time searches = max_rt_search_multiplier x max historical searches&lt;/H1&gt;

&lt;P&gt;max_rt_search_multiplier = 1&lt;/P&gt;

&lt;P&gt;on search head, Access controls » Roles » demorole&lt;/P&gt;

&lt;P&gt;User-level concurrent search jobs limit = 10&lt;/P&gt;

&lt;P&gt;now, the demorole role will choose which option? 8 or 10?&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 00:00:28 GMT</pubDate>
    <dc:creator>maniu1609</dc:creator>
    <dc:date>2020-09-30T00:00:28Z</dc:date>
    <item>
      <title>User level Concurrent search limits</title>
      <link>https://community.splunk.com/t5/Splunk-Search/User-level-Concurrent-search-limits/m-p/395995#M114965</link>
      <description>&lt;P&gt;Hi Everyone,&lt;BR /&gt;
On my system,  I have 2 CPU cores&lt;BR /&gt;
In $SPLUNKHOME/etc/system/local/limits.conf file I got below details,&lt;/P&gt;

&lt;P&gt;max_searches_per_cpu = 1&lt;/P&gt;

&lt;H1&gt;the base number of concurrent searches&lt;/H1&gt;

&lt;P&gt;base_max_searches = 6&lt;/P&gt;

&lt;H1&gt;max real-time searches = max_rt_search_multiplier x max historical searches&lt;/H1&gt;

&lt;P&gt;max_rt_search_multiplier = 1&lt;/P&gt;

&lt;P&gt;on search head, Access controls » Roles » demorole&lt;/P&gt;

&lt;P&gt;User-level concurrent search jobs limit = 10&lt;/P&gt;

&lt;P&gt;now, the demorole role will choose which option? 8 or 10?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:00:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/User-level-Concurrent-search-limits/m-p/395995#M114965</guid>
      <dc:creator>maniu1609</dc:creator>
      <dc:date>2020-09-30T00:00:28Z</dc:date>
    </item>
    <item>
      <title>Re: User level Concurrent search limits</title>
      <link>https://community.splunk.com/t5/Splunk-Search/User-level-Concurrent-search-limits/m-p/395996#M114966</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;As you have 2 CPU cores only, you can maximum run 8 searches concurrently based on default settings. Due to resource limitation splunk will not hit &lt;CODE&gt;User-level concurrent search jobs limit&lt;/CODE&gt; which is 10 in your case.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2019 13:41:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/User-level-Concurrent-search-limits/m-p/395996#M114966</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2019-04-11T13:41:07Z</dc:date>
    </item>
    <item>
      <title>Re: User level Concurrent search limits</title>
      <link>https://community.splunk.com/t5/Splunk-Search/User-level-Concurrent-search-limits/m-p/395997#M114967</link>
      <description>&lt;P&gt;Thanks @harsmarvania57. So whatever role we create should have user-level concurrent search limit less than number of concurrent search defined in limits.conf. Correct me if my understanding is wrong. Also I have one more query here. Should we define limits.conf at search head or in indexer?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2019 14:17:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/User-level-Concurrent-search-limits/m-p/395997#M114967</guid>
      <dc:creator>maniu1609</dc:creator>
      <dc:date>2019-04-11T14:17:51Z</dc:date>
    </item>
    <item>
      <title>Re: User level Concurrent search limits</title>
      <link>https://community.splunk.com/t5/Splunk-Search/User-level-Concurrent-search-limits/m-p/395998#M114968</link>
      <description>&lt;P&gt;Even if you provide higher user-level concurrent search limit then also it will not take into effect because before splunk will hit user-level concurrent search limit, it will hit CPU resource limitation so yes set user-level concurrent search limit less than or equal to your CPU core (Calculation is max_hist_searches =  max_searches_per_cpu x number_of_cpus + base_max_searches )&lt;/P&gt;

&lt;P&gt;Do you want to change any parameter value in limits.conf ? If yes then it should be on Search Heads but if you want to run on default settings then you do not need to set anything, splunk will automatically take default config from &lt;CODE&gt;$SPLUNK_HOME/etc/system/default/limits.conf&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:04:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/User-level-Concurrent-search-limits/m-p/395998#M114968</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2020-09-30T00:04:46Z</dc:date>
    </item>
    <item>
      <title>Re: User level Concurrent search limits</title>
      <link>https://community.splunk.com/t5/Splunk-Search/User-level-Concurrent-search-limits/m-p/395999#M114969</link>
      <description>&lt;P&gt;That's really great information. Thanks a lot @harsmarvania57&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2019 14:38:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/User-level-Concurrent-search-limits/m-p/395999#M114969</guid>
      <dc:creator>maniu1609</dc:creator>
      <dc:date>2019-04-11T14:38:11Z</dc:date>
    </item>
    <item>
      <title>Re: User level Concurrent search limits</title>
      <link>https://community.splunk.com/t5/Splunk-Search/User-level-Concurrent-search-limits/m-p/396000#M114970</link>
      <description>&lt;P&gt;You are welcome&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2019 14:42:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/User-level-Concurrent-search-limits/m-p/396000#M114970</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2019-04-11T14:42:22Z</dc:date>
    </item>
  </channel>
</rss>

