Security

Concurrent searches in Splunk (System wide & user specific)

splunker12er
Motivator

I do have Search head with 16 cores & 2Gb RAM Memory , using Splunk 5.x

As , per the calculation for Concurrent search , My system wide Concurrent search is 22

max_hist_searches =  max_searches_per_cpu x number_of_cpus + base_max_searches
max_hist_searches = 1 x 16 + 6 => 16 + 6 => 22

22 is the maximum number of concurrent search that my search hear can handle.

I do see for 'admin' role the values are as below :

Limit concurrent search jobs = 50
Limit concurrent real-time search jobs =100

These values are present by default in the Splunk web under authrorize.conf file.

How does the maximum concurrent search jobs limit can be 50 , when the system wide range itself 22 ?

Also , if I do specify the a count greater than the system wide limit does Splunk overrides the value within the allowed range ?

In this case , how do other users are affected , when 'admin' user takes the full control when he has maximum concurrent search limit ?

I am confused in this. Please advise on how to limit the users on concurrent search , considering the system wide limit.

0 Karma

ecambra_splunk
Splunk Employee
Splunk Employee

Most of the default settings are helpful for understanding how role administration works, but should be customized for your environment. You will never be able to exceed the hardware limits, but hitting the limit will result in queued searches and poor user experience.

Other things to watch out for are a high volume of real-time searches, scheduled searches and dashboards running inline searches. All of these are competing for the same pool of resources. So, if you have admin/power users who are creating and consuming without consideration for search-head resources it could cause issues for other users.

If you are able to, I would recommend installing the S.O.S. app. It's great for troubleshooting resource issues.
http://apps.splunk.com/app/748/

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...