The maximum RAM you want Splunk Enterprise to allocate in kilobytes. For example, 8GB is 8000000.
It appears Splunk do not really have a strong opinion on a minimum size now either. I think on RHEV Linux, the data segment size just defaults to unlimited anyway, or at least on our VM servers it does.
I don't believe setting this value alone helps protect Splunk from excessive memory use either. From what I can tell with googling about data segments, if it was indeed set to a value, then it does not even need to be set to an excessively large value. Happy to admit I'm no expert though.
Anyway, just wondering if anyone has some experience with setting this value in their environments, or even a view if this data segment size limit even really needs to be set at all - on Linux at least.