Monitoring Splunk

While performing the searches getting the warning messages like "usage limit exceed 500 MB"

gkumarashanmuga
Explorer

While performing the searches getting the "usage limit exceed 500 MB" warning messages , To overcome this error , We increased the default srchdiskquota limit from 500MB to 1000MB for the specifice roles in authorize.conf.
But still not resolving the same error persists.

Tags (1)
0 Karma

vr2312
Builder

@gkumarashanmugam

Are you by any chance using the trial version ?

Also as @richgalloway had suggested, try restarting the splunk instance after modifying the authorize.conf.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Did you restart Splunk after modifying authorize.conf?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...