<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: multi_threaded_setup parameter in limits.conf in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/multi-threaded-setup-parameter-in-limits-conf/m-p/73728#M18485</link>
    <description>&lt;P&gt;We just discovered that the default/limits.conf uses "false" as the value for multi_threaded_setup.  Now we wonder if using true/false would not work properly if set in local/limits.conf as per the spec file [0|1].&lt;/P&gt;

&lt;P&gt;From default/limits.conf:&lt;/P&gt;

&lt;H1&gt;whether to use multiple threads when setting up distributed search to multiple peers&lt;/H1&gt;

&lt;P&gt;multi_threaded_setup = false&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 15:45:33 GMT</pubDate>
    <dc:creator>the_wolverine</dc:creator>
    <dc:date>2020-09-28T15:45:33Z</dc:date>
    <item>
      <title>multi_threaded_setup parameter in limits.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/multi-threaded-setup-parameter-in-limits-conf/m-p/73725#M18482</link>
      <description>&lt;P&gt;We are currently looking at improving CPU optimization on the Splunk environment. We have found that the limits.conf contain the following option : &lt;/P&gt;

&lt;P&gt;multi_threaded_setup = [0|1] &lt;BR /&gt;
* Flag indicating whether to use multiple threads when setting up distributed search to multiple peers. &lt;BR /&gt;
* Defaults to false (0) &lt;/P&gt;

&lt;P&gt;I have done tests in the lab on both the search head and the indexer and I can't see any behavior change looking at the threads number. How should we activate this option and is it worth it? &lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:31:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/multi-threaded-setup-parameter-in-limits-conf/m-p/73725#M18482</guid>
      <dc:creator>splunkIT</dc:creator>
      <dc:date>2020-09-28T12:31:26Z</dc:date>
    </item>
    <item>
      <title>Re: multi_threaded_setup parameter in limits.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/multi-threaded-setup-parameter-in-limits-conf/m-p/73726#M18483</link>
      <description>&lt;P&gt;The multi_threaded_setup parameter in limits.conf does not have any direct relation to CPU optimization. This parameter may be helpful for distributed search environment where you have dozens of search PEERS implemented, but in most case this parameter should be left alone. Generally, we don't recommend users to make any modification to the limits.conf file, with the exceptions of some specific cases. &lt;/P&gt;

&lt;P&gt;Perhaps this Splunk Answers thread may help in answering your questions in regarding to CPU optimization: &lt;/P&gt;

&lt;P&gt;&lt;A href="http://splunk-base.splunk.com/answers/12027/singlemulti-threading-cpu" target="_blank"&gt;http://splunk-base.splunk.com/answers/12027/singlemulti-threading-cpu&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:31:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/multi-threaded-setup-parameter-in-limits-conf/m-p/73726#M18483</guid>
      <dc:creator>splunkIT</dc:creator>
      <dc:date>2020-09-28T12:31:30Z</dc:date>
    </item>
    <item>
      <title>Re: multi_threaded_setup parameter in limits.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/multi-threaded-setup-parameter-in-limits-conf/m-p/73727#M18484</link>
      <description>&lt;P&gt;Correct, this parameter only controls multi-threading of the connection establishment to many distributed search peers. Typically the time take for this is negligible, but if you have lots of them it may matter. HOWEVER, due to issues in the SSL libraries that Splunk uses today (September 2012), if you want to use this parameter, you must disable SSL on the search peers splunkd.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2012 22:14:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/multi-threaded-setup-parameter-in-limits-conf/m-p/73727#M18484</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2012-09-27T22:14:12Z</dc:date>
    </item>
    <item>
      <title>Re: multi_threaded_setup parameter in limits.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/multi-threaded-setup-parameter-in-limits-conf/m-p/73728#M18485</link>
      <description>&lt;P&gt;We just discovered that the default/limits.conf uses "false" as the value for multi_threaded_setup.  Now we wonder if using true/false would not work properly if set in local/limits.conf as per the spec file [0|1].&lt;/P&gt;

&lt;P&gt;From default/limits.conf:&lt;/P&gt;

&lt;H1&gt;whether to use multiple threads when setting up distributed search to multiple peers&lt;/H1&gt;

&lt;P&gt;multi_threaded_setup = false&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 15:45:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/multi-threaded-setup-parameter-in-limits-conf/m-p/73728#M18485</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2020-09-28T15:45:33Z</dc:date>
    </item>
    <item>
      <title>Re: multi_threaded_setup parameter in limits.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/multi-threaded-setup-parameter-in-limits-conf/m-p/73729#M18486</link>
      <description>&lt;P&gt;SplunkIT:  "This parameter may be helpful for distributed search environment where you have dozens of search heads"  Do you mean "search peers" (typically, indexers) OR did you mean search HEADS?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2014 22:53:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/multi-threaded-setup-parameter-in-limits-conf/m-p/73729#M18486</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2014-01-29T22:53:35Z</dc:date>
    </item>
    <item>
      <title>Re: multi_threaded_setup parameter in limits.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/multi-threaded-setup-parameter-in-limits-conf/m-p/73730#M18487</link>
      <description>&lt;P&gt;Search peers/indexers.&lt;/P&gt;

&lt;P&gt;multi_threaded_setup = [0|1]&lt;BR /&gt;
* Flag indicating whether to use multiple threads when setting up distributed search to multiple peers.&lt;BR /&gt;
* Defaults to false (0)&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 15:45:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/multi-threaded-setup-parameter-in-limits-conf/m-p/73730#M18487</guid>
      <dc:creator>splunkIT</dc:creator>
      <dc:date>2020-09-28T15:45:41Z</dc:date>
    </item>
  </channel>
</rss>

