<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Changing the Ulimits for openfiles in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Changing-the-Ulimits-for-openfiles/m-p/318532#M163551</link>
    <description>&lt;P&gt;I personally change the ulimits on all splunk servers ( for consistency ) &lt;/P&gt;

&lt;P&gt;I also use the initd method to ensure ulimits are 'stickey'&lt;BR /&gt;&lt;BR /&gt;
** note you will need to full restart the server ( reboot ) for the changes to take effect as they are in the initd running /opt/splunk/bin/splunk restart wont put the required change in place . &lt;/P&gt;</description>
    <pubDate>Fri, 19 Jan 2018 17:59:23 GMT</pubDate>
    <dc:creator>klaxdal</dc:creator>
    <dc:date>2018-01-19T17:59:23Z</dc:date>
    <item>
      <title>Changing the Ulimits for openfiles</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Changing-the-Ulimits-for-openfiles/m-p/318521#M163540</link>
      <description>&lt;P&gt;How can we change the ulimits of Splunk to the desired value ? &lt;BR /&gt;
I have edited the /etc/security/limits.conf file and rebooted the instance &lt;BR /&gt;
I have added  "*                -       nofile          64000" to the file .&lt;BR /&gt;
But Splunk still shows only 4096. How can we change this value . &lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2018 18:39:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Changing-the-Ulimits-for-openfiles/m-p/318521#M163540</guid>
      <dc:creator>nawazns5038</dc:creator>
      <dc:date>2018-01-17T18:39:09Z</dc:date>
    </item>
    <item>
      <title>Re: Changing the Ulimits for openfiles</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Changing-the-Ulimits-for-openfiles/m-p/318522#M163541</link>
      <description>&lt;P&gt;Did you set both hard and soft limits?&lt;/P&gt;

&lt;P&gt;Take a look at this - &lt;/P&gt;

&lt;P&gt;&lt;A href="https://www.cyberciti.biz/faq/linux-increase-the-maximum-number-of-open-files/"&gt;https://www.cyberciti.biz/faq/linux-increase-the-maximum-number-of-open-files/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;You may be seeing the soft limit, even though you have raised the system wide hard limit&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2018 18:45:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Changing-the-Ulimits-for-openfiles/m-p/318522#M163541</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2018-01-17T18:45:50Z</dc:date>
    </item>
    <item>
      <title>Re: Changing the Ulimits for openfiles</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Changing-the-Ulimits-for-openfiles/m-p/318523#M163542</link>
      <description>&lt;P&gt;Try setting it in the Splunk initd&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/223838/why-are-my-ulimits-settings-not-being-respected-on.html"&gt;https://answers.splunk.com/answers/223838/why-are-my-ulimits-settings-not-being-respected-on.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2018 18:48:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Changing-the-Ulimits-for-openfiles/m-p/318523#M163542</guid>
      <dc:creator>klaxdal</dc:creator>
      <dc:date>2018-01-17T18:48:42Z</dc:date>
    </item>
    <item>
      <title>Re: Changing the Ulimits for openfiles</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Changing-the-Ulimits-for-openfiles/m-p/318524#M163543</link>
      <description>&lt;P&gt;hey have a look at this&lt;BR /&gt;
you can create a script!&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/223838/why-are-my-ulimits-settings-not-being-respected-on.html"&gt;https://answers.splunk.com/answers/223838/why-are-my-ulimits-settings-not-being-respected-on.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Also&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/13313/how-to-tune-ulimit-on-my-server.html"&gt;https://answers.splunk.com/answers/13313/how-to-tune-ulimit-on-my-server.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="https://www.cyberciti.biz/faq/linux-increase-the-maximum-number-of-open-files/"&gt;https://www.cyberciti.biz/faq/linux-increase-the-maximum-number-of-open-files/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2018 18:51:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Changing-the-Ulimits-for-openfiles/m-p/318524#M163543</guid>
      <dc:creator>mayurr98</dc:creator>
      <dc:date>2018-01-17T18:51:28Z</dc:date>
    </item>
    <item>
      <title>Re: Changing the Ulimits for openfiles</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Changing-the-Ulimits-for-openfiles/m-p/318525#M163544</link>
      <description>&lt;P&gt;Is it necessary to change the ulimts of all the Splunk instances or just the indexers ?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2018 23:28:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Changing-the-Ulimits-for-openfiles/m-p/318525#M163544</guid>
      <dc:creator>nawazns5038</dc:creator>
      <dc:date>2018-01-17T23:28:42Z</dc:date>
    </item>
    <item>
      <title>Re: Changing the Ulimits for openfiles</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Changing-the-Ulimits-for-openfiles/m-p/318526#M163545</link>
      <description>&lt;P&gt;Is it necessary to change the ulimts of all the Splunk instances or just the indexers ?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2018 23:28:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Changing-the-Ulimits-for-openfiles/m-p/318526#M163545</guid>
      <dc:creator>nawazns5038</dc:creator>
      <dc:date>2018-01-17T23:28:48Z</dc:date>
    </item>
    <item>
      <title>Re: Changing the Ulimits for openfiles</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Changing-the-Ulimits-for-openfiles/m-p/318527#M163546</link>
      <description>&lt;P&gt;Is it necessary to change the ulimts of all the Splunk instances or just the indexers ?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2018 23:29:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Changing-the-Ulimits-for-openfiles/m-p/318527#M163546</guid>
      <dc:creator>nawazns5038</dc:creator>
      <dc:date>2018-01-17T23:29:07Z</dc:date>
    </item>
    <item>
      <title>Re: Changing the Ulimits for openfiles</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Changing-the-Ulimits-for-openfiles/m-p/318528#M163547</link>
      <description>&lt;P&gt;Any standard procedure for changing the ulimits of the servers ? &lt;BR /&gt;
I tried  "ulimit -n 65536" command on all the indexers and did a rolling restart on the servers. Still there is no change in the ulimits. and edited the /etc/init.d/splunk script as mentioned. &lt;/P&gt;

&lt;P&gt;Is it the right process to be followed ? &lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2018 02:06:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Changing-the-Ulimits-for-openfiles/m-p/318528#M163547</guid>
      <dc:creator>nawazns5038</dc:creator>
      <dc:date>2018-01-18T02:06:21Z</dc:date>
    </item>
    <item>
      <title>Re: Changing the Ulimits for openfiles</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Changing-the-Ulimits-for-openfiles/m-p/318529#M163548</link>
      <description>&lt;P&gt;Any standard procedure for changing the ulimits of the servers ? &lt;BR /&gt;
I tried  "ulimit -n 65536" command on all the indexers and did a rolling restart on the servers. Still there is no change in the ulimits. and edited the /etc/init.d/splunk script as mentioned. &lt;/P&gt;

&lt;P&gt;Is it the right process to be followed ? &lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2018 02:06:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Changing-the-Ulimits-for-openfiles/m-p/318529#M163548</guid>
      <dc:creator>nawazns5038</dc:creator>
      <dc:date>2018-01-18T02:06:33Z</dc:date>
    </item>
    <item>
      <title>Re: Changing the Ulimits for openfiles</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Changing-the-Ulimits-for-openfiles/m-p/318530#M163549</link>
      <description>&lt;P&gt;Any standard procedure for changing the ulimits of the servers ? &lt;BR /&gt;
I tried  "ulimit -n 65536" command on all the indexers and did a rolling restart on the servers. Still there is no change in the ulimits. and edited the /etc/init.d/splunk script as mentioned. &lt;/P&gt;

&lt;P&gt;Is it the right process to be followed ? &lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2018 02:06:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Changing-the-Ulimits-for-openfiles/m-p/318530#M163549</guid>
      <dc:creator>nawazns5038</dc:creator>
      <dc:date>2018-01-18T02:06:44Z</dc:date>
    </item>
    <item>
      <title>Re: Changing the Ulimits for openfiles</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Changing-the-Ulimits-for-openfiles/m-p/318531#M163550</link>
      <description>&lt;P&gt;see this splunk official doc&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/ulimitErrors"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/ulimitErrors&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2018 06:43:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Changing-the-Ulimits-for-openfiles/m-p/318531#M163550</guid>
      <dc:creator>mayurr98</dc:creator>
      <dc:date>2018-01-18T06:43:14Z</dc:date>
    </item>
    <item>
      <title>Re: Changing the Ulimits for openfiles</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Changing-the-Ulimits-for-openfiles/m-p/318532#M163551</link>
      <description>&lt;P&gt;I personally change the ulimits on all splunk servers ( for consistency ) &lt;/P&gt;

&lt;P&gt;I also use the initd method to ensure ulimits are 'stickey'&lt;BR /&gt;&lt;BR /&gt;
** note you will need to full restart the server ( reboot ) for the changes to take effect as they are in the initd running /opt/splunk/bin/splunk restart wont put the required change in place . &lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2018 17:59:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Changing-the-Ulimits-for-openfiles/m-p/318532#M163551</guid>
      <dc:creator>klaxdal</dc:creator>
      <dc:date>2018-01-19T17:59:23Z</dc:date>
    </item>
    <item>
      <title>Re: Changing the Ulimits for openfiles</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Changing-the-Ulimits-for-openfiles/m-p/318533#M163552</link>
      <description>&lt;P&gt;how can reboot all the servers of a cluster safely ? &lt;BR /&gt;
Rebooting is fine if its a single instance &lt;/P&gt;</description>
      <pubDate>Mon, 22 Jan 2018 19:36:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Changing-the-Ulimits-for-openfiles/m-p/318533#M163552</guid>
      <dc:creator>nawazns5038</dc:creator>
      <dc:date>2018-01-22T19:36:06Z</dc:date>
    </item>
    <item>
      <title>Re: Changing the Ulimits for openfiles</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Changing-the-Ulimits-for-openfiles/m-p/318534#M163553</link>
      <description>&lt;P&gt;No, you will need to restart the OS, not just splunk.&lt;BR /&gt;
Take a look at maintenance mode&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.1/Indexer/Usemaintenancemode"&gt;http://docs.splunk.com/Documentation/Splunk/7.0.1/Indexer/Usemaintenancemode&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jan 2018 19:50:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Changing-the-Ulimits-for-openfiles/m-p/318534#M163553</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2018-01-22T19:50:15Z</dc:date>
    </item>
    <item>
      <title>Re: Changing the Ulimits for openfiles</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Changing-the-Ulimits-for-openfiles/m-p/318535#M163554</link>
      <description>&lt;P&gt;@nickhillscpl , how can we restart the OS without effecting Splunk service. &lt;BR /&gt;
Maintenance mode only restarts the Splunk service. &lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2018 00:46:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Changing-the-Ulimits-for-openfiles/m-p/318535#M163554</guid>
      <dc:creator>nawazns5038</dc:creator>
      <dc:date>2018-01-25T00:46:18Z</dc:date>
    </item>
    <item>
      <title>Re: Changing the Ulimits for openfiles</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Changing-the-Ulimits-for-openfiles/m-p/318536#M163555</link>
      <description>&lt;P&gt;Maintenance mode is useful if you are restarting a cluster peer.  If the machine does not restart within the cluster timeout, a fix up operation will begin on all missing replicas. You want this to happen if one of your peers fails, but not if your rebooting. &lt;/P&gt;

&lt;P&gt;Enabling maint. Mode prevents the cluster performing any fixup operations while you restart your servers. &lt;/P&gt;

&lt;P&gt;To perform a clean os restart, enable maintenance mode on your cluster master, then run ‘splunk offline’ on a peer, and restart the os. When that peer is back up and connected to the cluster, repeat the process for other peers. &lt;BR /&gt;
Then disable maint. Mode&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2018 07:11:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Changing-the-Ulimits-for-openfiles/m-p/318536#M163555</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2018-01-25T07:11:47Z</dc:date>
    </item>
  </channel>
</rss>

