<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to estimate Splunk memory usage? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-estimate-Splunk-memory-usage/m-p/186848#M53817</link>
    <description>&lt;P&gt;Is there a reason you're still running on Splunk 5.0.4? Typically it's not recommend to start altering those defaults. There have been several improvements between the current version of Splunk and the one you're running. &lt;/P&gt;</description>
    <pubDate>Sun, 19 Jun 2016 22:12:49 GMT</pubDate>
    <dc:creator>ryanoconnor</dc:creator>
    <dc:date>2016-06-19T22:12:49Z</dc:date>
    <item>
      <title>How to estimate Splunk memory usage?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-estimate-Splunk-memory-usage/m-p/186847#M53816</link>
      <description>&lt;P&gt;Could please someone tell what is the best value I should set for the "&lt;STRONG&gt;max_mem_usage_mb&lt;/STRONG&gt;" and "&lt;STRONG&gt;max_rawsize_perchunk&lt;/STRONG&gt;" ?&lt;/P&gt;

&lt;P&gt;In my search, an indexer outputs following the error message "ERROR databasePartitionPolicy - Max Raw Size Limit Exceeded", and a search head also outputs "WARN  StatsProcessor - reached limit max_mem_usage_mb=200, results may be incomplete."&lt;BR /&gt;
These errors must be related to parameters "max_mem_usage_mb" and "max_rawsize_perchunk," so I'm planning to change these parameters from default value.&lt;/P&gt;

&lt;P&gt;Although, these parameters default values are here.&lt;BR /&gt;
max_mem_usage_mb = 200 (MB)&lt;BR /&gt;
max_rawsize_perchunk = 100 (MB)&lt;BR /&gt;
actual memory usage of splunkd process goes up to more than 1.3 Gbyte (in TOP command RES size), which does not make sense for me.&lt;/P&gt;

&lt;P&gt;Anyway, does anyone know good way to estimate the size of memory for splunk usage?&lt;/P&gt;

&lt;P&gt;some information here&lt;BR /&gt;
my splunk version: 5.0.4&lt;BR /&gt;
search event counts: 50M+ event (w/ 3 indexers and 1 search head)&lt;BR /&gt;
use command: search, stats and more&lt;/P&gt;

&lt;P&gt;thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:21:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-estimate-Splunk-memory-usage/m-p/186847#M53816</guid>
      <dc:creator>mpfsplunk01</dc:creator>
      <dc:date>2020-09-28T17:21:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to estimate Splunk memory usage?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-estimate-Splunk-memory-usage/m-p/186848#M53817</link>
      <description>&lt;P&gt;Is there a reason you're still running on Splunk 5.0.4? Typically it's not recommend to start altering those defaults. There have been several improvements between the current version of Splunk and the one you're running. &lt;/P&gt;</description>
      <pubDate>Sun, 19 Jun 2016 22:12:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-estimate-Splunk-memory-usage/m-p/186848#M53817</guid>
      <dc:creator>ryanoconnor</dc:creator>
      <dc:date>2016-06-19T22:12:49Z</dc:date>
    </item>
  </channel>
</rss>

