Monitoring Splunk

What is the max value I can set for max_mem_usage_mb based on our system configuration?


We have Splunk 6.1.5 search head systems with large amount of memory (128 GB) and 20 cores. The expected daily log volume is 500GB and the total number of concurrent users is 5. The expected concurrent searches count is approximately 30 for this system.

What is the max_mem_usage_mb value that I can set? Is there any formula to arrive at a safe number? The last thing that I do not want is to face OOM errors by setting large value for this attribute.

0 Karma


How much to assign to max_mem_usage_mb should be based more on the number of results in your searches than on the size of your system. If you find your search results are being truncated then you should increase the value of max_mem_usage_mb. Doubling the value to 400 MB shouldn't harm your system.

If this reply helps you, Karma would be appreciated.
0 Karma

Path Finder

Do we need to set this limit on SH or on indexer?


0 Karma
Get Updates on the Splunk Community!

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

Observability Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestSplunk APM's New Tag Filter ExperienceSplunk APM has updated ...

Security Newsletter Updates | March 2023

 March 2023 | Check out the latest and greatestUnify Your Security Operations with Splunk Mission Control The ...