Reporting

How to configure settings for the "nobody" user and what is the max srchDiskQuota setting?

claudiaG
Engager

We currently have an issue with our "nobody" user in splunk whom we assign all our scheduled reports to. we are reaching daily the disk quota limit and  a lot of searches are getting skipped.

Message:

"The maximum disk usage quota for this user has been reached."

Now I want to increase the "srchDiskQuota" in the authorize.conf.  But having two questions:

1. Is it correct that if we want to assign anything to the "nobody" user we need to do this for [default] since the "nobody" user isnt assigned to any role? Or is the user actually part of the role "splunk-system-role"?

2. How can I find out what would be my maximum setting for the "srchDiskQuota" to not brake my system?

Thanks for a short feedback.

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

I recommend creating a role and account only for running scheduled searches.  Don't use 'nobody'.  Having a role just for scheduled searches makes it much easier to manage the resources it can use.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Streamline Data Ingestion With Deployment Server Essentials

REGISTER NOW!Every day the list of sources Admins are responsible for gets bigger and bigger, often making the ...

Remediate Threats Faster and Simplify Investigations With Splunk Enterprise Security ...

REGISTER NOW!Join us for a Tech Talk around our latest release of Splunk Enterprise Security 7.2! We’ll walk ...

Introduction to Splunk AI

WATCH NOWHow are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. ...