<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to prevent &amp;quot;max concurrent searches reached&amp;quot; messages on the distributed management console? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-prevent-quot-max-concurrent-searches-reached-quot/m-p/200435#M58105</link>
    <description>&lt;P&gt;I agree with @ykou. I also run my DMC on a tiny VM and ALWAYS run out of concurrent searches when I load the DMC's default dashboard. I trust that they'll just queue up and I don't mind waiting a moment so I ignore it.&lt;/P&gt;

&lt;P&gt;It's merely informational to let you know that the other searches are going to queue since you hit the max. I only really see it on that first dashboard since so much happens on there.&lt;/P&gt;

&lt;P&gt;If its truly an issue, you could increase the DMC cpu's or modify the per cpu limits.conf setting. I'm not sure its worth it though.&lt;/P&gt;</description>
    <pubDate>Mon, 13 Jun 2016 19:56:35 GMT</pubDate>
    <dc:creator>sloshburch</dc:creator>
    <dc:date>2016-06-13T19:56:35Z</dc:date>
    <item>
      <title>How to prevent "max concurrent searches reached" messages on the distributed management console?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-prevent-quot-max-concurrent-searches-reached-quot/m-p/200432#M58102</link>
      <description>&lt;P&gt;I've configured a dev Splunk 6.4 env, and noticed that my Distributed Management Console is getting "max concurrent searches reached" messages.  Sooooo, since the DMC isn't part of the Search Head Cluster and can't benefit from the improved scheduling, and since the DMC is probably going to add more and more searches over time as it develops... I'm looking for idea on how to prevent this situation, since the DMC is supposed to be runnable from a "smallish" VM (6 vcpu's).&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2016 18:28:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-prevent-quot-max-concurrent-searches-reached-quot/m-p/200432#M58102</guid>
      <dc:creator>a212830</dc:creator>
      <dc:date>2016-04-13T18:28:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent "max concurrent searches reached" messages on the distributed management console?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-prevent-quot-max-concurrent-searches-reached-quot/m-p/200433#M58103</link>
      <description>&lt;P&gt;DMC fires searches only when you open a page or a dashboard. We try to limit the total number of searches on each page/dashboard. &lt;/P&gt;

&lt;P&gt;Reaching max concurrent searches wouldn't prevent DMC from working, the searches are just in the waiting queue and will run as soon as  other searches finished. &lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2016 18:48:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-prevent-quot-max-concurrent-searches-reached-quot/m-p/200433#M58103</guid>
      <dc:creator>ykou_splunk</dc:creator>
      <dc:date>2016-04-13T18:48:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent "max concurrent searches reached" messages on the distributed management console?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-prevent-quot-max-concurrent-searches-reached-quot/m-p/200434#M58104</link>
      <description>&lt;P&gt;True, but if it's a trouble-shooting tool, then I need the most recent information, and I might not have it.  Seems to be an area that was overlooked, in all honesty... more and more searches are going to be added to the DMC, which is going to require it to be a bigger server. &lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2016 19:42:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-prevent-quot-max-concurrent-searches-reached-quot/m-p/200434#M58104</guid>
      <dc:creator>a212830</dc:creator>
      <dc:date>2016-04-13T19:42:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent "max concurrent searches reached" messages on the distributed management console?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-prevent-quot-max-concurrent-searches-reached-quot/m-p/200435#M58105</link>
      <description>&lt;P&gt;I agree with @ykou. I also run my DMC on a tiny VM and ALWAYS run out of concurrent searches when I load the DMC's default dashboard. I trust that they'll just queue up and I don't mind waiting a moment so I ignore it.&lt;/P&gt;

&lt;P&gt;It's merely informational to let you know that the other searches are going to queue since you hit the max. I only really see it on that first dashboard since so much happens on there.&lt;/P&gt;

&lt;P&gt;If its truly an issue, you could increase the DMC cpu's or modify the per cpu limits.conf setting. I'm not sure its worth it though.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2016 19:56:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-prevent-quot-max-concurrent-searches-reached-quot/m-p/200435#M58105</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2016-06-13T19:56:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent "max concurrent searches reached" messages on the distributed management console?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-prevent-quot-max-concurrent-searches-reached-quot/m-p/200436#M58106</link>
      <description>&lt;P&gt;what about the DMC alerts?&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2017 18:10:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-prevent-quot-max-concurrent-searches-reached-quot/m-p/200436#M58106</guid>
      <dc:creator>dfqobvbkmnpi</dc:creator>
      <dc:date>2017-05-03T18:10:22Z</dc:date>
    </item>
  </channel>
</rss>

