I seem to be throttled when executing a lot of splunk queries. my jobs get queued up. Is there anything I can do to gain insights into why a particular user is being throttled?
If you are Splunk administrator or have access to internal logs, you will see something like below in splunkd.log
The reason might vary depending on what limit you are hitting.
WARN DispatchManager - Queued job id =63D19E6EB819, search = 'search index=blah blah ' , reason = "The maximum number of concurrent historical searches for this user based on their role quota has been reached. concurrency_limit=15"