Monitoring Splunk

How is Max_size_kb determined

richnavis
Contributor

I am looking to troubleshoot performance problems (Indexing latency) on my splunk indexers. I noticed that there is a lot of blocking, apparently due to the max_size_kb being reached on the indexqueue. I am not seeing any disk latency, so not sure why this is happening..

Anyone know how the max_size_kb is determined, and if it is changeable?

1 Solution

ChrisG
Splunk Employee
Splunk Employee

Yes, it's in the queue settings of $SPLUNK/etc/system/local/server.conf (see http://docs.splunk.com/Documentation/Splunk/4.3/Admin/Serverconf for reference).

View solution in original post

ChrisG
Splunk Employee
Splunk Employee

Yes, it's in the queue settings of $SPLUNK/etc/system/local/server.conf (see http://docs.splunk.com/Documentation/Splunk/4.3/Admin/Serverconf for reference).

Get Updates on the Splunk Community!

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...