<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: The maximum number of historical concurrent system-wide searches has been reached. current=8 maximum=8 in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/The-maximum-number-of-historical-concurrent-system-wide-searches/m-p/94421#M24335</link>
    <description>&lt;P&gt;About the job summary :&lt;BR /&gt;
you have some funny searches with just a "|" in it.&lt;BR /&gt;
please find the admin of the SessionApp and tell him to stop running those searches.&lt;/P&gt;

&lt;P&gt;about the hardware :&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;i have installed 2 splunk instances in the same VM.. and it have 2 cpu cores. &lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;Sad, you can barely run 2 realtime searches with that.&lt;/P&gt;

&lt;P&gt;FYI the base hardware is 2 quad cores on a physical server. &lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.1/Installation/Referencehardware"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.1/Installation/Referencehardware&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 28 Jan 2013 17:55:42 GMT</pubDate>
    <dc:creator>yannK</dc:creator>
    <dc:date>2013-01-28T17:55:42Z</dc:date>
    <item>
      <title>The maximum number of historical concurrent system-wide searches has been reached. current=8 maximum=8</title>
      <link>https://community.splunk.com/t5/Splunk-Search/The-maximum-number-of-historical-concurrent-system-wide-searches/m-p/94410#M24324</link>
      <description>&lt;P&gt;HI ,&lt;BR /&gt;
Even if i just started my splunk instance, my views are loading with this error. I am sure that only one search is currently running. How can i troubleshoot this?&lt;BR /&gt;
Please help&lt;BR /&gt;
Thank you&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2013 05:32:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/The-maximum-number-of-historical-concurrent-system-wide-searches/m-p/94410#M24324</guid>
      <dc:creator>smolcj</dc:creator>
      <dc:date>2013-01-22T05:32:17Z</dc:date>
    </item>
    <item>
      <title>Re: The maximum number of historical concurrent system-wide searches has been reached. current=8 maximum=8</title>
      <link>https://community.splunk.com/t5/Splunk-Search/The-maximum-number-of-historical-concurrent-system-wide-searches/m-p/94411#M24325</link>
      <description>&lt;P&gt;Open the job inspector (top right menu) and check how many searches are running.&lt;BR /&gt;
You may have scheduled summary searches, the apps like deployment-monitor etc ....&lt;/P&gt;

&lt;P&gt;The maximum number of searches is proportional of the number of cores on the system, so you could improve the hardware.&lt;BR /&gt;
see &lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.1/Deploy/Accommodatemanysimultaneoussearches"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.1/Deploy/Accommodatemanysimultaneoussearches&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jan 2013 17:11:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/The-maximum-number-of-historical-concurrent-system-wide-searches/m-p/94411#M24325</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2013-01-23T17:11:29Z</dc:date>
    </item>
    <item>
      <title>Re: The maximum number of historical concurrent system-wide searches has been reached. current=8 maximum=8</title>
      <link>https://community.splunk.com/t5/Splunk-Search/The-maximum-number-of-historical-concurrent-system-wide-searches/m-p/94412#M24326</link>
      <description>&lt;P&gt;my splunk app is under testing and i am using a Virtual machine for the same. i have 2 cpu cores ..  i tried changing the default values in authorize.conf. &lt;BR /&gt;
my issue is as soon as i start the splunk instance , i am facing this error in the first search itself.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jan 2013 05:12:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/The-maximum-number-of-historical-concurrent-system-wide-searches/m-p/94412#M24326</guid>
      <dc:creator>smolcj</dc:creator>
      <dc:date>2013-01-25T05:12:12Z</dc:date>
    </item>
    <item>
      <title>Re: The maximum number of historical concurrent system-wide searches has been reached. current=8 maximum=8</title>
      <link>https://community.splunk.com/t5/Splunk-Search/The-maximum-number-of-historical-concurrent-system-wide-searches/m-p/94413#M24327</link>
      <description>&lt;P&gt;Is there any limit for searches in a view? Currently i have 2 pages with 6 panels each.If I include 12 panels in one page, will the searches become slow?&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jan 2013 06:49:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/The-maximum-number-of-historical-concurrent-system-wide-searches/m-p/94413#M24327</guid>
      <dc:creator>bellaed</dc:creator>
      <dc:date>2013-01-25T06:49:55Z</dc:date>
    </item>
    <item>
      <title>Re: The maximum number of historical concurrent system-wide searches has been reached. current=8 maximum=8</title>
      <link>https://community.splunk.com/t5/Splunk-Search/The-maximum-number-of-historical-concurrent-system-wide-searches/m-p/94414#M24328</link>
      <description>&lt;P&gt;no the extra searches will simply be skipped.&lt;/P&gt;

&lt;P&gt;see answer for the system wide search limit on the other question : &lt;BR /&gt;
&lt;A href="http://splunk-base.splunk.com/answers/73074/limit-for-searches-in-a-page"&gt;http://splunk-base.splunk.com/answers/73074/limit-for-searches-in-a-page&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jan 2013 16:35:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/The-maximum-number-of-historical-concurrent-system-wide-searches/m-p/94414#M24328</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2013-01-25T16:35:15Z</dc:date>
    </item>
    <item>
      <title>Re: The maximum number of historical concurrent system-wide searches has been reached. current=8 maximum=8</title>
      <link>https://community.splunk.com/t5/Splunk-Search/The-maximum-number-of-historical-concurrent-system-wide-searches/m-p/94415#M24329</link>
      <description>&lt;P&gt;i have installed 2 splunk instances in the same VM.. and it have 2 cpu cores. Eve if i am using one instance at a time, the very first search itself is giving this message and it is slowing down my searches..&lt;BR /&gt;
is this a splunk bug, or do i have to look into any of my configs? i went through limits.conf as well i didn't find anything wrong there also.. &lt;BR /&gt;
please help&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jan 2013 11:46:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/The-maximum-number-of-historical-concurrent-system-wide-searches/m-p/94415#M24329</guid>
      <dc:creator>smolcj</dc:creator>
      <dc:date>2013-01-28T11:46:07Z</dc:date>
    </item>
    <item>
      <title>Re: The maximum number of historical concurrent system-wide searches has been reached. current=8 maximum=8</title>
      <link>https://community.splunk.com/t5/Splunk-Search/The-maximum-number-of-historical-concurrent-system-wide-searches/m-p/94416#M24330</link>
      <description>&lt;P&gt;Yann has already answered this. You just have searches running you haven't spotted. Also bear in mind that on startup a lot of scheduled searches tend to fire which can have an impact. Frankly if you're running two instances on a 2 core machine you should just accept that you're going to receive these messages.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jan 2013 12:01:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/The-maximum-number-of-historical-concurrent-system-wide-searches/m-p/94416#M24330</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2013-01-28T12:01:33Z</dc:date>
    </item>
    <item>
      <title>Re: The maximum number of historical concurrent system-wide searches has been reached. current=8 maximum=8</title>
      <link>https://community.splunk.com/t5/Splunk-Search/The-maximum-number-of-historical-concurrent-system-wide-searches/m-p/94417#M24331</link>
      <description>&lt;P&gt;&lt;IMG src="http://splunk-base.splunk.com//storage/Untitled_9.png" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jan 2013 12:35:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/The-maximum-number-of-historical-concurrent-system-wide-searches/m-p/94417#M24331</guid>
      <dc:creator>smolcj</dc:creator>
      <dc:date>2013-01-28T12:35:54Z</dc:date>
    </item>
    <item>
      <title>Re: The maximum number of historical concurrent system-wide searches has been reached. current=8 maximum=8</title>
      <link>https://community.splunk.com/t5/Splunk-Search/The-maximum-number-of-historical-concurrent-system-wide-searches/m-p/94418#M24332</link>
      <description>&lt;P&gt;This is my output when i tried reading job inspector...&lt;BR /&gt;
i aouldnt able to find the issue with this input.&lt;BR /&gt;
Somebody pls help, whats wrong with this&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jan 2013 12:37:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/The-maximum-number-of-historical-concurrent-system-wide-searches/m-p/94418#M24332</guid>
      <dc:creator>smolcj</dc:creator>
      <dc:date>2013-01-28T12:37:31Z</dc:date>
    </item>
    <item>
      <title>Re: The maximum number of historical concurrent system-wide searches has been reached. current=8 maximum=8</title>
      <link>https://community.splunk.com/t5/Splunk-Search/The-maximum-number-of-historical-concurrent-system-wide-searches/m-p/94419#M24333</link>
      <description>&lt;P&gt;and what is the output if you expand it to include all apps and all owners?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jan 2013 12:39:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/The-maximum-number-of-historical-concurrent-system-wide-searches/m-p/94419#M24333</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2013-01-28T12:39:05Z</dc:date>
    </item>
    <item>
      <title>Re: The maximum number of historical concurrent system-wide searches has been reached. current=8 maximum=8</title>
      <link>https://community.splunk.com/t5/Splunk-Search/The-maximum-number-of-historical-concurrent-system-wide-searches/m-p/94420#M24334</link>
      <description>&lt;P&gt;&lt;IMG src="http://splunk-base.splunk.com//storage/Untitled_11.png" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jan 2013 12:45:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/The-maximum-number-of-historical-concurrent-system-wide-searches/m-p/94420#M24334</guid>
      <dc:creator>smolcj</dc:creator>
      <dc:date>2013-01-28T12:45:05Z</dc:date>
    </item>
    <item>
      <title>Re: The maximum number of historical concurrent system-wide searches has been reached. current=8 maximum=8</title>
      <link>https://community.splunk.com/t5/Splunk-Search/The-maximum-number-of-historical-concurrent-system-wide-searches/m-p/94421#M24335</link>
      <description>&lt;P&gt;About the job summary :&lt;BR /&gt;
you have some funny searches with just a "|" in it.&lt;BR /&gt;
please find the admin of the SessionApp and tell him to stop running those searches.&lt;/P&gt;

&lt;P&gt;about the hardware :&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;i have installed 2 splunk instances in the same VM.. and it have 2 cpu cores. &lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;Sad, you can barely run 2 realtime searches with that.&lt;/P&gt;

&lt;P&gt;FYI the base hardware is 2 quad cores on a physical server. &lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.1/Installation/Referencehardware"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.1/Installation/Referencehardware&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jan 2013 17:55:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/The-maximum-number-of-historical-concurrent-system-wide-searches/m-p/94421#M24335</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2013-01-28T17:55:42Z</dc:date>
    </item>
    <item>
      <title>Re: The maximum number of historical concurrent system-wide searches has been reached. current=8 maximum=8</title>
      <link>https://community.splunk.com/t5/Splunk-Search/The-maximum-number-of-historical-concurrent-system-wide-searches/m-p/94422#M24336</link>
      <description>&lt;P&gt;Thanks Yannk, But i haven't created any searches like this. How to debug the issue? i have used appencols for many of my searches and when i count the searches using append or appendcols and there are 5.. is that the reason ?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jan 2013 04:16:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/The-maximum-number-of-historical-concurrent-system-wide-searches/m-p/94422#M24336</guid>
      <dc:creator>smolcj</dc:creator>
      <dc:date>2013-01-29T04:16:22Z</dc:date>
    </item>
    <item>
      <title>Re: The maximum number of historical concurrent system-wide searches has been reached. current=8 maximum=8</title>
      <link>https://community.splunk.com/t5/Splunk-Search/The-maximum-number-of-historical-concurrent-system-wide-searches/m-p/94423#M24337</link>
      <description>&lt;P&gt;@smolcj, the app named Infa-Session is the one generating those queries. Disable the app to stop the searches.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Dec 2014 22:32:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/The-maximum-number-of-historical-concurrent-system-wide-searches/m-p/94423#M24337</guid>
      <dc:creator>vqd361</dc:creator>
      <dc:date>2014-12-12T22:32:22Z</dc:date>
    </item>
    <item>
      <title>Re: The maximum number of historical concurrent system-wide searches has been reached. current=8 maximum=8</title>
      <link>https://community.splunk.com/t5/Splunk-Search/The-maximum-number-of-historical-concurrent-system-wide-searches/m-p/94424#M24338</link>
      <description>&lt;P&gt;I had this problem recently and it was for a tricky/silly reason.  I got tired of the &lt;CODE&gt;dispatch&lt;/CODE&gt; directory being tied to the root volume and getting  &lt;CODE&gt;The minimum free disk space (5000MB) reached for /opt/splunk/var/run/splunk/dispatch&lt;/CODE&gt; errors, so i created a 10G volume and mounted it over dispatch BUT I neglected to make it writable by the user running splunkd (i.e. "splunk").  In such a situation, 14 searches will start, but not really, and none will be able to complete so you get hung.  I discovered the problem by going to the search head CLI and doing this (because I could not search against _*):&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;tail -f $SPLUNK_HOME/var/log/splunk/*
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Very quickly I saw logs like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;10-21-2016 12:02:10.208 -0400 ERROR SearchScheduler - failed to rm -r /opt/splunk/var/run/splunk/dispatch/scheduler__nobody_c3BsdW5rX21vbml0b3JpbmdfY29uc29sZQ__RMD54740dfff07b17ef1_at_1477065699_0: No such file or directory
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;In other words, it was trying to remove files that it was not able to create.  OOPS!  A simple &lt;CODE&gt;chmod&lt;/CODE&gt; later and all was good again.&lt;/P&gt;</description>
      <pubDate>Sat, 22 Oct 2016 14:02:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/The-maximum-number-of-historical-concurrent-system-wide-searches/m-p/94424#M24338</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2016-10-22T14:02:14Z</dc:date>
    </item>
  </channel>
</rss>

