Monitoring Splunk

throttling users

dtakacssplunk
Explorer

I seem to be throttled when executing a lot of splunk queries. my jobs get queued up. Is there anything I can do to gain insights into why a particular user is being throttled?

Tags (1)
0 Karma

pradeepkumarg
Influencer

If you are Splunk administrator or have access to internal logs, you will see something like below in splunkd.log

The reason might vary depending on what limit you are hitting.

 WARN  DispatchManager - Queued job id =63D19E6EB819, search = 'search index=blah blah ' , reason = "The maximum number of concurrent historical searches for this user based on their role quota has been reached. concurrency_limit=15"
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...