All Apps and Add-ons

Counting open files with lsof in Unix app

timmy13
Communicator

I need a way to determine how many files a particular user has open at any given time. This data exists in the output of the lsof data in the *nix app. BUt since it's one big field, I am unsure of how to parse it to get counts of files by user. Any ideas?

0 Karma
1 Solution

araitz
Splunk Employee
Splunk Employee

Did you try:

index=os sourcetype=lsof | multikv

View solution in original post

harish_l
New Member

what is the maximum ulimit is splunk, by default minimum is 64000. anyone please let me know the maximum ulimit setting?

0 Karma

araitz
Splunk Employee
Splunk Employee

Did you try:

index=os sourcetype=lsof | multikv

timmy13
Communicator

Nice! Sometimes the simplest solution evades me. Thanks!

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...