Monitoring Splunk

Memory tuning guide?

daniel333
Builder

All,

I am receiving this error message in a relatgively small Splunk stack that is brand new.

3 errors occurred while the search was executing. Therefore, search results might be incomplete. Hide errors.
[someserver.domain.com] Events might not be returned in sub-second order due to search memory limits. See search.log for more information. Increase the value of the following limits.conf setting:[search]:max_rawsize_perchunk.

Is there a tuning guide for this? Any alerts or dashboards I should be looking at?

Labels (1)
0 Karma

jessec_splunk
Splunk Employee
Splunk Employee
0 Karma

daniel333
Builder

Bumped to 1gig from 100megs and problem went away. DMC says system resources are solid still. Any downside to increasing that number?

0 Karma
Get Updates on the Splunk Community!

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...