Reporting

How do i set savedsearchs limit.conf in 8 core server?

YUNHYEONG
Explorer

hello splunker.

i have about 50 savedsearchs for only 1 summary index.

It starts at half an hour intervals and saevedsearchs have many subsearch. ( command : map, foreach, streamstats etc..)

I use server which have 8 core and 62GB RAM

How do i set limits.conf?

[search]
base_max_search = ??
max_searches_per_cpu = ??

[scheduler]
max_searches_perc = ??

Please recommend other options.

Thank you ! Please help me. xD

0 Karma

adonio
Ultra Champion

first and foremost, your server doesnt meet minimum requirements as described in hardware reference.
second, why not spread your searches across the clock? for example, instead of running your searches on minute 30 and 60 / 0
run them on minute 1,2,3,4 ... 31,32,33,34 ...
then use the earliest and latest attributes to align the data

0 Karma

YUNHYEONG
Explorer

how do you think 8 core server limit.conf setting.

0 Karma
Get Updates on the Splunk Community!

Infographic provides the TL;DR for the 2024 Splunk Career Impact Report

We’ve been buzzing with excitement about the recent validation of Splunk Education! The 2024 Splunk Career ...

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...