Deployment Architecture

Skipped scheduler searches :Your maximum number of concurrent searches has been reached. usage=3104 quota=3000 user=admin.

ankithnageshshe
Path Finder

Hello All,

Lately I see a lot of skipped scheduler searches in my search head cluster (3) with the reason "Your maximum number of concurrent searches has been reached. usage=3104 quota=3000 user=admin".

If I view from DMC console, I see not more than 200 searches run for each search head summing up to almost 600~700 searches for admin user in the last 4 hours.

I do not see any active running searches neither in the search head job manager nor on the Scheduler activity in the DMC.
However I see a lot of deferred jobs for one of the search head in DMC console.

Do you think rolling restart of search heads will help here as I do not see any search related issue here.

Regards,
Ankith

Tags (1)
0 Karma
1 Solution

ankithnageshshe
Path Finder

Hi All,

Rolling restart of the SHC fixed the issue. Brought down the deferred jobs from 90K to 2K after the rolling restart.

But I'am trying to understand the difference between concurrency search quota for user( admin) and the historical system wide search quota. How this will impact my SHC performance?

Regards,
Ankith

View solution in original post

0 Karma

ankithnageshshe
Path Finder

Hi All,

Rolling restart of the SHC fixed the issue. Brought down the deferred jobs from 90K to 2K after the rolling restart.

But I'am trying to understand the difference between concurrency search quota for user( admin) and the historical system wide search quota. How this will impact my SHC performance?

Regards,
Ankith

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...