Getting Data In

Where is the correct configuration file located in order to modify the Windows 2012 R2 ulimit?

molinarf
Communicator

I run health check on my Splunk Enterprise 6.6.0 server running on Windows 2012 R2. I end up with the warning "One or more Splunk instances are running on a host that has on or more resource limits set below official recommendations." This is related to ulimits.data_segment_size being unknown. I have spent hours looking for which file the configuration is set, but I cannot find it. Can anyone point me to where I can modify the configurations?

Thank you,

0 Karma
1 Solution

MuS
Legend

Hi molinarf,

This setting is not applicable to Windows servers, ulimits is a *nix setting as described in the docs here http://docs.splunk.com/Documentation/Splunk/latest/Installation/Systemrequirements#Considerations_re...

Most likely this is the reason why the size of ulimits.data_segment_size is unknown, because it does not exist on Windows.

Maybe worth to open a bug report?

Hope this helps ...

cheers, MuS

View solution in original post

0 Karma

MuS
Legend

Hi molinarf,

This setting is not applicable to Windows servers, ulimits is a *nix setting as described in the docs here http://docs.splunk.com/Documentation/Splunk/latest/Installation/Systemrequirements#Considerations_re...

Most likely this is the reason why the size of ulimits.data_segment_size is unknown, because it does not exist on Windows.

Maybe worth to open a bug report?

Hope this helps ...

cheers, MuS

0 Karma

Jarohnimo
Builder

I'm getting this warning too (Windows 2012 R2) and spent half the day finding out how much i don't know about linux. Splunk is built on linux, it works better on linux, linux is king ... now that we have established that.

They need to fix this or do a better job at making sure the product works correctly on both Windows and Linux platforms. or perhaps only support linux and give up on the Windows Platform.. either way whatever you put out it should work and be applicable.

0 Karma

molinarf
Communicator

Thanks MuS. I was beginning to wonder why all my searches kept bringing up references to unix. I think it might be worth it to open a bug report for future installers of Splunk on Windows servers.

0 Karma
Get Updates on the Splunk Community!

Enter the Dashboard Challenge and Watch the .conf24 Global Broadcast!

The Splunk Community Dashboard Challenge is still happening, and it's not too late to enter for the week of ...

Join Us at the Builder Bar at .conf24 – Empowering Innovation and Collaboration

What is the Builder Bar? The Builder Bar is more than just a place; it's a hub of creativity, collaboration, ...

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...