I've been running into errors where larger searches are getting cancelled. I read this could be due to running out of memory. I looked at my search head which is running on a server with 32 gb but only using 8gb (numbers from monitoring console)
I'm assuming there's some setting to increase how much memory is allocated to splunk but i haven't found it. I've seen settings for memory per search - is the overall memory calculated from allowed number of searches and memory per search?
thanks