<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WARN: Search auto-finalized after disk usage limit (500MB) reached. WARN: Search auto-finalized after disk usage limit (500MB) reached. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/WARN-Search-auto-finalized-after-disk-usage-limit-500MB-reached/m-p/89065#M22810</link>
    <description>&lt;P&gt;I think that authorize.conf need to be on each Search Head splunk/etc/system/local not on shared folder or inside an app...&lt;/P&gt;</description>
    <pubDate>Mon, 12 Mar 2012 18:50:37 GMT</pubDate>
    <dc:creator>MarioM</dc:creator>
    <dc:date>2012-03-12T18:50:37Z</dc:date>
    <item>
      <title>WARN: Search auto-finalized after disk usage limit (500MB) reached. WARN: Search auto-finalized after disk usage limit (500MB) reached.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/WARN-Search-auto-finalized-after-disk-usage-limit-500MB-reached/m-p/89062#M22807</link>
      <description>&lt;P&gt;I'm running a cli search via command line in a search server.&lt;/P&gt;

&lt;P&gt;I've already updated srchDiskQuota = 3000 to the role of the user running this query.&lt;BR /&gt;
But I'm still getting this error, and only get 1/4 size of a full day's worth of events.&lt;/P&gt;

&lt;P&gt;WARN: Search auto-finalized after disk usage limit (500MB) reached.&lt;/P&gt;

&lt;P&gt;Is there anything else I need to check? How can I resolve this warning?&lt;/P&gt;</description>
      <pubDate>Sat, 10 Mar 2012 02:06:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/WARN-Search-auto-finalized-after-disk-usage-limit-500MB-reached/m-p/89062#M22807</guid>
      <dc:creator>suhprano</dc:creator>
      <dc:date>2012-03-10T02:06:53Z</dc:date>
    </item>
    <item>
      <title>Re: WARN: Search auto-finalized after disk usage limit (500MB) reached. WARN: Search auto-finalized after disk usage limit (500MB) reached.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/WARN-Search-auto-finalized-after-disk-usage-limit-500MB-reached/m-p/89063#M22808</link>
      <description>&lt;P&gt;where did you put the authorize.conf with the srchDiskQuota parameter? it needs to be in &lt;CODE&gt;splunk/etc/system/local&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Did you restart splunk service?&lt;/P&gt;

&lt;P&gt;could you post your authorize.conf?&lt;/P&gt;

&lt;P&gt;&lt;A href="http://wiki.splunk.com/Community:TroubleshootingSearchQuotas"&gt;Troubleshooting Search Quotas&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 11 Mar 2012 10:10:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/WARN-Search-auto-finalized-after-disk-usage-limit-500MB-reached/m-p/89063#M22808</guid>
      <dc:creator>MarioM</dc:creator>
      <dc:date>2012-03-11T10:10:03Z</dc:date>
    </item>
    <item>
      <title>Re: WARN: Search auto-finalized after disk usage limit (500MB) reached. WARN: Search auto-finalized after disk usage limit (500MB) reached.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/WARN-Search-auto-finalized-after-disk-usage-limit-500MB-reached/m-p/89064#M22809</link>
      <description>&lt;P&gt;Couple of details...&lt;BR /&gt;
I'm running a 2 search server model, but only running the query on search01.&lt;BR /&gt;
Both search servers are pulling configs in a shared nfs directory, and I can verify it has the right configs when I run ./splunk cmd btool authorize list&lt;/P&gt;

&lt;P&gt;Authorize.conf is in &lt;BR /&gt;
/opt/splunk/(nfs symlink dir)/etc/apps/search_base/local/&lt;/P&gt;

&lt;P&gt;I restarted the service.&lt;/P&gt;

&lt;P&gt;Here's my authorize.conf for this particular user's role:&lt;BR /&gt;
[role_bot-bi]&lt;BR /&gt;
importRoles = bi&lt;BR /&gt;
rtSrchJobsQuota = 0&lt;BR /&gt;
srchDiskQuota = 3000&lt;BR /&gt;
srchJobsQuota = 0&lt;/P&gt;</description>
      <pubDate>Sun, 11 Mar 2012 17:55:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/WARN-Search-auto-finalized-after-disk-usage-limit-500MB-reached/m-p/89064#M22809</guid>
      <dc:creator>suhprano</dc:creator>
      <dc:date>2012-03-11T17:55:00Z</dc:date>
    </item>
    <item>
      <title>Re: WARN: Search auto-finalized after disk usage limit (500MB) reached. WARN: Search auto-finalized after disk usage limit (500MB) reached.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/WARN-Search-auto-finalized-after-disk-usage-limit-500MB-reached/m-p/89065#M22810</link>
      <description>&lt;P&gt;I think that authorize.conf need to be on each Search Head splunk/etc/system/local not on shared folder or inside an app...&lt;/P&gt;</description>
      <pubDate>Mon, 12 Mar 2012 18:50:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/WARN-Search-auto-finalized-after-disk-usage-limit-500MB-reached/m-p/89065#M22810</guid>
      <dc:creator>MarioM</dc:creator>
      <dc:date>2012-03-12T18:50:37Z</dc:date>
    </item>
  </channel>
</rss>

