I'm seeing this warning for my search query:
WARN: mvexpand output will be truncated due to excessive memory usage
All Splunk answers point me to changing the max_mem_usage_mb in limits.conf but I'm using Splunk Cloud and I don't see a setting under
Settings -> All configurations
You cannot modify this yourself with Splunk Cloud. You will need to open a support ticket and they will assist.
However, Cloud is tuned for the instances provisioned and mvexpand is very expensive to use, especially in large datasets.. So you may want to look at tuning your search.
You cannot modify this yourself with Splunk Cloud. You will need to open a support ticket and they will assist.
However, Cloud is tuned for the instances provisioned and mvexpand is very expensive to use, especially in large datasets.. So you may want to look at tuning your search.