Deployment Architecture

Too many open files

khyoung7410
Communicator

Hi


Too many open files error message in my indexer.


so, ulimit(file opens) values change to 4,096(soft and hard).


However, the error message still occurs.


How are you?


Thank you.

Tags (2)
0 Karma
1 Solution

jbsplunk
Splunk Employee
Splunk Employee

Hello,

Chances are high that you need to increase this number again. With 4.3 and the introduction of bloom filters, it's important to understand that the number of open files used could be increased significantly. I would suggest starting with 8192.

http://blogs.splunk.com/2011/11/21/whats-your-ulimit/

View solution in original post

jbsplunk
Splunk Employee
Splunk Employee

Hello,

Chances are high that you need to increase this number again. With 4.3 and the introduction of bloom filters, it's important to understand that the number of open files used could be increased significantly. I would suggest starting with 8192.

http://blogs.splunk.com/2011/11/21/whats-your-ulimit/

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...