Other Usage

How to configure settings for the "nobody" user and what is the max srchDiskQuota setting?

claudiaG
Engager

We currently have an issue with our "nobody" user in splunk whom we assign all our scheduled reports to. we are reaching daily the disk quota limit and  a lot of searches are getting skipped.

Message:

"The maximum disk usage quota for this user has been reached."

Now I want to increase the "srchDiskQuota" in the authorize.conf.  But having two questions:

1. Is it correct that if we want to assign anything to the "nobody" user we need to do this for [default] since the "nobody" user isnt assigned to any role? Or is the user actually part of the role "splunk-system-role"?

2. How can I find out what would be my maximum setting for the "srchDiskQuota" to not brake my system?

Thanks for a short feedback.

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

I recommend creating a role and account only for running scheduled searches.  Don't use 'nobody'.  Having a role just for scheduled searches makes it much easier to manage the resources it can use.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...