Dashboards & Visualizations

The maximum disk usage quota for this user has been reached. Use the Job Manager to delete some of your saved search results.

mbagali_splunk
Splunk Employee
Splunk Employee

Dashboards loading slow and waiting for queued job. Getting below errors:

Error 1: The maximum disk usage quota for this user has been reached. Use the Job Manager to delete some of your saved search results.

Error 2: The maximum number of concurrent historical searches for this user based on their role quota has been reached

Tags (1)
0 Karma
1 Solution

mbagali_splunk
Splunk Employee
Splunk Employee

For Error 1: The maximum disk usage quota for this user has been reached. Use the Job Manager to delete some of your saved search results.

Work around would be to increase disk usage quota for user in authorize.conf .

srchDiskQuota =

By default it is 100 MB, you can set it to higher value.

For Error 2: The maximum number of concurrent historical searches for this user based on their role quota has been reached

Work around would be to increase search job quota for the user:

srchJobsQuota =

* Maximum number of concurrently running historical searches a member of this role can have. * This excludes real-time searches, see rtSrchJobsQuota. * Defaults to 3.

Increase it to a higher value

View solution in original post

mbagali_splunk
Splunk Employee
Splunk Employee

For Error 1: The maximum disk usage quota for this user has been reached. Use the Job Manager to delete some of your saved search results.

Work around would be to increase disk usage quota for user in authorize.conf .

srchDiskQuota =

By default it is 100 MB, you can set it to higher value.

For Error 2: The maximum number of concurrent historical searches for this user based on their role quota has been reached

Work around would be to increase search job quota for the user:

srchJobsQuota =

* Maximum number of concurrently running historical searches a member of this role can have. * This excludes real-time searches, see rtSrchJobsQuota. * Defaults to 3.

Increase it to a higher value

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...

Index This | Divide 100 by half. What do you get?

November 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

❄️ Celebrate the season with our December lineup of Community Office Hours, Tech Talks, and Webinars! ...