<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Search auto-finalized after disk usage limit (100mb) reached - What does this mean? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Search-auto-finalized-after-disk-usage-limit-100mb-reached-What/m-p/296794#M163895</link>
    <description>&lt;P&gt;You must be running a heavy search which , for it's processing, taking more than 100mb of dispatch directory and thus getting &lt;A href="https://docs.splunk.com/Splexicon:Finalize"&gt;finalized&lt;/A&gt;. You should look at optimizing your search to reduce it's footprint (recommended) or adjust srchDiskQuota for your role in authorize.conf to increase the disk usage limit.&lt;/P&gt;</description>
    <pubDate>Fri, 05 Jan 2018 19:20:14 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2018-01-05T19:20:14Z</dc:date>
    <item>
      <title>Search auto-finalized after disk usage limit (100mb) reached - What does this mean?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-auto-finalized-after-disk-usage-limit-100mb-reached-What/m-p/296793#M163894</link>
      <description>&lt;P&gt;Started getting Search auto-finalized after disk usage limit (100mb) reached - What does this mean?&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jan 2018 19:12:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-auto-finalized-after-disk-usage-limit-100mb-reached-What/m-p/296793#M163894</guid>
      <dc:creator>simpkins1958</dc:creator>
      <dc:date>2018-01-05T19:12:05Z</dc:date>
    </item>
    <item>
      <title>Re: Search auto-finalized after disk usage limit (100mb) reached - What does this mean?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-auto-finalized-after-disk-usage-limit-100mb-reached-What/m-p/296794#M163895</link>
      <description>&lt;P&gt;You must be running a heavy search which , for it's processing, taking more than 100mb of dispatch directory and thus getting &lt;A href="https://docs.splunk.com/Splexicon:Finalize"&gt;finalized&lt;/A&gt;. You should look at optimizing your search to reduce it's footprint (recommended) or adjust srchDiskQuota for your role in authorize.conf to increase the disk usage limit.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jan 2018 19:20:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-auto-finalized-after-disk-usage-limit-100mb-reached-What/m-p/296794#M163895</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-01-05T19:20:14Z</dc:date>
    </item>
    <item>
      <title>Re: Search auto-finalized after disk usage limit (100mb) reached - What does this mean?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-auto-finalized-after-disk-usage-limit-100mb-reached-What/m-p/296795#M163896</link>
      <description>&lt;P&gt;Basically, you ran out of space.  &lt;/P&gt;

&lt;P&gt;The first thing you might consider doing is using the &lt;CODE&gt;| fields&lt;/CODE&gt; command at the earliest point possible to eliminate everything but the fields you need.  Other than that, you'd have to post a non-confidential version of the search to answers, in a separate question, and we could see how to help you make it more space-efficient.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jan 2018 22:46:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-auto-finalized-after-disk-usage-limit-100mb-reached-What/m-p/296795#M163896</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2018-01-05T22:46:36Z</dc:date>
    </item>
    <item>
      <title>Re: Search auto-finalized after disk usage limit (100mb) reached - What does this mean?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-auto-finalized-after-disk-usage-limit-100mb-reached-What/m-p/296796#M163897</link>
      <description>&lt;P&gt;Hey&lt;/P&gt;

&lt;P&gt;First,I think you need to optimise your search query &lt;BR /&gt;
and secondly in search head  &lt;CODE&gt;$SPLUNK_HOME/etc/system/local/authorize.conf&lt;/CODE&gt; put&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[your_role]
srchDiskQuota   = 500
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Maximum amount of disk space (MB) that can be used by search jobs of a user that belongs to this role which is &lt;CODE&gt;500 MB&lt;/CODE&gt; by default its &lt;CODE&gt;100 MB&lt;/CODE&gt; &lt;BR /&gt;
&lt;CODE&gt;your_role&lt;/CODE&gt; is allowed to take up 500 megabytes total on disk for all their jobs.&lt;/P&gt;

&lt;P&gt;refer this doc &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Admin/authorizeconf#authorize.conf.example" target="test_blank"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Admin/authorizeconf#authorize.conf.example&lt;/A&gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I hope that helps you!&lt;/P&gt;</description>
      <pubDate>Sat, 06 Jan 2018 10:17:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-auto-finalized-after-disk-usage-limit-100mb-reached-What/m-p/296796#M163897</guid>
      <dc:creator>mayurr98</dc:creator>
      <dc:date>2018-01-06T10:17:54Z</dc:date>
    </item>
    <item>
      <title>Re: Search auto-finalized after disk usage limit (100mb) reached - What does this mean?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-auto-finalized-after-disk-usage-limit-100mb-reached-What/m-p/296797#M163898</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;When we receive this message or warning saying 100MB threshold is reached, the output what we see, do we say whatever it has given with the search executed, is that accurate data??&lt;/P&gt;

&lt;P&gt;Or this data cannot be considered as accurate because of 100MB threshold??&lt;/P&gt;

&lt;P&gt;All, I wanted to understand is even with this 100MB threshold, the results which is given do we say it is accurate or it is partial and cannot be considred as Accurate enough and it needs to be optimised or run by a search admin with high disk quota to get accurate results...&lt;/P&gt;

&lt;P&gt;Please advise&lt;/P&gt;</description>
      <pubDate>Mon, 29 Oct 2018 08:21:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-auto-finalized-after-disk-usage-limit-100mb-reached-What/m-p/296797#M163898</guid>
      <dc:creator>sandeepshah81</dc:creator>
      <dc:date>2018-10-29T08:21:03Z</dc:date>
    </item>
  </channel>
</rss>

