Dashboards & Visualizations

How to Add RAM capacity Size to Splunk

wahluf
Explorer

I processed 100 million events. from the data I use to present several kinds of visualization. but this makes memory limited so that an error appears like the following

Dag Execution Exception: Search has been cancelled. Search auto-canceled.

 

 

Labels (1)
Tags (1)

inventsekar
SplunkTrust
SplunkTrust

Hi @wahluf if you update us your search query, then, we can fine-tune it.  so that, the error may go away. 

otherwise, you will need to add Ram as you said. 

 

Adding RAM is simply the linux admin task. @nwuest 's reply got some nice details as well. 

0 Karma

thambisetty
SplunkTrust
SplunkTrust

if you think you have enough memory then the issue could be with search you are running. there could be chance of improving search performance as well. 

————————————
If this helps, give a like below.

nwuest
Path Finder

Hi @wahluf,

You are correct that you need to add RAM to your Splunk Searchhead to improve your search capabilities and performance.
See here: Searches are auto-cancelled 

Do you happen to know if your Searchhead is a physical server or a virtual machine?

  • If it is a physical server, you will have to do some homework in finding what ram is currently installed on your server and if there are slots for expansion. Also, if your server has two cpu's you will need to buy equal ram modules for each processor otherwise they won't be recognized as part of a memory imbalance between the CPU's.

  • If it is a virtual machine, find out if you have additional resources to allocate to the Searchhead.
    * NOTE: Work with the necessary parties to ensure that you are able to take what you can.

    1. To add ram you will need to "configure" the VM and sometimes this will require that you have to turn off the VM to be able to add/change the resources for that VM.

    2. Once the VM is off, you should be able to add the newly allocated RAM to the VM and then save the changes.

    3. Now you can turn back on the VM, do ensure that the Splunk Service comes back up and the web page is accessible.
    * NOTE: If you do have to turn off the Searchhead VM, do let the responsible parties/persons that use the Searchhead of its upcoming maintenance. It will save you a headache and phones calls asking why the server went down.

    4. Depending on if you are able to "hot-add" RAM to the Searchhead VM or not, some good housekeeping would be to restart the guest OS which in turn would restart the Splunk Service. This will ensure that Splunk recognizes the newly added RAM and will be able to use it going forward in a clean manner.
    See Here: Hot-add RAM to a Splunk Searchhead 

We do hope this helps you out with your question!

V/R,
nwuest

Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...