Dashboards & Visualizations

The maximum disk usage quota for this user has been reached. Use the Job Manager to delete some of your saved search results.

mbagali_splunk
Splunk Employee
Splunk Employee

Dashboards loading slow and waiting for queued job. Getting below errors:

Error 1: The maximum disk usage quota for this user has been reached. Use the Job Manager to delete some of your saved search results.

Error 2: The maximum number of concurrent historical searches for this user based on their role quota has been reached

Tags (1)
0 Karma
1 Solution

mbagali_splunk
Splunk Employee
Splunk Employee

For Error 1: The maximum disk usage quota for this user has been reached. Use the Job Manager to delete some of your saved search results.

Work around would be to increase disk usage quota for user in authorize.conf .

srchDiskQuota =

By default it is 100 MB, you can set it to higher value.

For Error 2: The maximum number of concurrent historical searches for this user based on their role quota has been reached

Work around would be to increase search job quota for the user:

srchJobsQuota =

* Maximum number of concurrently running historical searches a member of this role can have. * This excludes real-time searches, see rtSrchJobsQuota. * Defaults to 3.

Increase it to a higher value

View solution in original post

mbagali_splunk
Splunk Employee
Splunk Employee

For Error 1: The maximum disk usage quota for this user has been reached. Use the Job Manager to delete some of your saved search results.

Work around would be to increase disk usage quota for user in authorize.conf .

srchDiskQuota =

By default it is 100 MB, you can set it to higher value.

For Error 2: The maximum number of concurrent historical searches for this user based on their role quota has been reached

Work around would be to increase search job quota for the user:

srchJobsQuota =

* Maximum number of concurrently running historical searches a member of this role can have. * This excludes real-time searches, see rtSrchJobsQuota. * Defaults to 3.

Increase it to a higher value

Get Updates on the Splunk Community!

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...