Deployment Architecture

Too many open files

khyoung7410
Communicator

Hi


Too many open files error message in my indexer.


so, ulimit(file opens) values change to 4,096(soft and hard).


However, the error message still occurs.


How are you?


Thank you.

Tags (2)
0 Karma
1 Solution

jbsplunk
Splunk Employee
Splunk Employee

Hello,

Chances are high that you need to increase this number again. With 4.3 and the introduction of bloom filters, it's important to understand that the number of open files used could be increased significantly. I would suggest starting with 8192.

http://blogs.splunk.com/2011/11/21/whats-your-ulimit/

View solution in original post

jbsplunk
Splunk Employee
Splunk Employee

Hello,

Chances are high that you need to increase this number again. With 4.3 and the introduction of bloom filters, it's important to understand that the number of open files used could be increased significantly. I would suggest starting with 8192.

http://blogs.splunk.com/2011/11/21/whats-your-ulimit/

Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...