Dashboards & Visualizations

How to Add RAM capacity Size to Splunk

wahluf
Explorer

I processed 100 million events. from the data I use to present several kinds of visualization. but this makes memory limited so that an error appears like the following

Dag Execution Exception: Search has been cancelled. Search auto-canceled.

 

 

Tags (1)

inventsekar
SplunkTrust
SplunkTrust

Hi @wahluf if you update us your search query, then, we can fine-tune it.  so that, the error may go away. 

otherwise, you will need to add Ram as you said. 

 

Adding RAM is simply the linux admin task. @nwuest 's reply got some nice details as well. 

0 Karma

thambisetty
SplunkTrust
SplunkTrust

if you think you have enough memory then the issue could be with search you are running. there could be chance of improving search performance as well. 

————————————
If this helps, give a like below.

nwuest
Path Finder

Hi @wahluf,

You are correct that you need to add RAM to your Splunk Searchhead to improve your search capabilities and performance.
See here: Searches are auto-cancelled 

Do you happen to know if your Searchhead is a physical server or a virtual machine?

  • If it is a physical server, you will have to do some homework in finding what ram is currently installed on your server and if there are slots for expansion. Also, if your server has two cpu's you will need to buy equal ram modules for each processor otherwise they won't be recognized as part of a memory imbalance between the CPU's.

  • If it is a virtual machine, find out if you have additional resources to allocate to the Searchhead.
    * NOTE: Work with the necessary parties to ensure that you are able to take what you can.

    1. To add ram you will need to "configure" the VM and sometimes this will require that you have to turn off the VM to be able to add/change the resources for that VM.

    2. Once the VM is off, you should be able to add the newly allocated RAM to the VM and then save the changes.

    3. Now you can turn back on the VM, do ensure that the Splunk Service comes back up and the web page is accessible.
    * NOTE: If you do have to turn off the Searchhead VM, do let the responsible parties/persons that use the Searchhead of its upcoming maintenance. It will save you a headache and phones calls asking why the server went down.

    4. Depending on if you are able to "hot-add" RAM to the Searchhead VM or not, some good housekeeping would be to restart the guest OS which in turn would restart the Splunk Service. This will ensure that Splunk recognizes the newly added RAM and will be able to use it going forward in a clean manner.
    See Here: Hot-add RAM to a Splunk Searchhead 

We do hope this helps you out with your question!

V/R,
nwuest

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...