Monitoring Splunk

Memory tuning guide?

Builder

All,

I am receiving this error message in a relatgively small Splunk stack that is brand new.

3 errors occurred while the search was executing. Therefore, search results might be incomplete. Hide errors.
[someserver.domain.com] Events might not be returned in sub-second order due to search memory limits. See search.log for more information. Increase the value of the following limits.conf setting:[search]:max_rawsize_perchunk.

Is there a tuning guide for this? Any alerts or dashboards I should be looking at?

Labels (1)
0 Karma

Splunk Employee
Splunk Employee
0 Karma

Builder

Bumped to 1gig from 100megs and problem went away. DMC says system resources are solid still. Any downside to increasing that number?

0 Karma
Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes
and swag!