Security

Concurrent searches in Splunk (System wide & user specific)

splunker12er
Motivator

I do have Search head with 16 cores & 2Gb RAM Memory , using Splunk 5.x

As , per the calculation for Concurrent search , My system wide Concurrent search is 22

max_hist_searches =  max_searches_per_cpu x number_of_cpus + base_max_searches
max_hist_searches = 1 x 16 + 6 => 16 + 6 => 22

22 is the maximum number of concurrent search that my search hear can handle.

I do see for 'admin' role the values are as below :

Limit concurrent search jobs = 50
Limit concurrent real-time search jobs =100

These values are present by default in the Splunk web under authrorize.conf file.

How does the maximum concurrent search jobs limit can be 50 , when the system wide range itself 22 ?

Also , if I do specify the a count greater than the system wide limit does Splunk overrides the value within the allowed range ?

In this case , how do other users are affected , when 'admin' user takes the full control when he has maximum concurrent search limit ?

I am confused in this. Please advise on how to limit the users on concurrent search , considering the system wide limit.

0 Karma

ecambra_splunk
Splunk Employee
Splunk Employee

Most of the default settings are helpful for understanding how role administration works, but should be customized for your environment. You will never be able to exceed the hardware limits, but hitting the limit will result in queued searches and poor user experience.

Other things to watch out for are a high volume of real-time searches, scheduled searches and dashboards running inline searches. All of these are competing for the same pool of resources. So, if you have admin/power users who are creating and consuming without consideration for search-head resources it could cause issues for other users.

If you are able to, I would recommend installing the S.O.S. app. It's great for troubleshooting resource issues.
http://apps.splunk.com/app/748/

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...