Deployment Architecture

Too many open files

khyoung7410
Communicator

Hi


Too many open files error message in my indexer.


so, ulimit(file opens) values change to 4,096(soft and hard).


However, the error message still occurs.


How are you?


Thank you.

Tags (2)
0 Karma
1 Solution

jbsplunk
Splunk Employee
Splunk Employee

Hello,

Chances are high that you need to increase this number again. With 4.3 and the introduction of bloom filters, it's important to understand that the number of open files used could be increased significantly. I would suggest starting with 8192.

http://blogs.splunk.com/2011/11/21/whats-your-ulimit/

View solution in original post

jbsplunk
Splunk Employee
Splunk Employee

Hello,

Chances are high that you need to increase this number again. With 4.3 and the introduction of bloom filters, it's important to understand that the number of open files used could be increased significantly. I would suggest starting with 8192.

http://blogs.splunk.com/2011/11/21/whats-your-ulimit/

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...