Monitoring Splunk

Memory tuning guide?

daniel333
Builder

All,

I am receiving this error message in a relatgively small Splunk stack that is brand new.

3 errors occurred while the search was executing. Therefore, search results might be incomplete. Hide errors.
[someserver.domain.com] Events might not be returned in sub-second order due to search memory limits. See search.log for more information. Increase the value of the following limits.conf setting:[search]:max_rawsize_perchunk.

Is there a tuning guide for this? Any alerts or dashboards I should be looking at?

Labels (1)
0 Karma

jessec_splunk
Splunk Employee
Splunk Employee
0 Karma

daniel333
Builder

Bumped to 1gig from 100megs and problem went away. DMC says system resources are solid still. Any downside to increasing that number?

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...