Security

Concurrent searches in Splunk (System wide & user specific)

splunker12er
Motivator

I do have Search head with 16 cores & 2Gb RAM Memory , using Splunk 5.x

As , per the calculation for Concurrent search , My system wide Concurrent search is 22

max_hist_searches =  max_searches_per_cpu x number_of_cpus + base_max_searches
max_hist_searches = 1 x 16 + 6 => 16 + 6 => 22

22 is the maximum number of concurrent search that my search hear can handle.

I do see for 'admin' role the values are as below :

Limit concurrent search jobs = 50
Limit concurrent real-time search jobs =100

These values are present by default in the Splunk web under authrorize.conf file.

How does the maximum concurrent search jobs limit can be 50 , when the system wide range itself 22 ?

Also , if I do specify the a count greater than the system wide limit does Splunk overrides the value within the allowed range ?

In this case , how do other users are affected , when 'admin' user takes the full control when he has maximum concurrent search limit ?

I am confused in this. Please advise on how to limit the users on concurrent search , considering the system wide limit.

0 Karma

ecambra_splunk
Splunk Employee
Splunk Employee

Most of the default settings are helpful for understanding how role administration works, but should be customized for your environment. You will never be able to exceed the hardware limits, but hitting the limit will result in queued searches and poor user experience.

Other things to watch out for are a high volume of real-time searches, scheduled searches and dashboards running inline searches. All of these are competing for the same pool of resources. So, if you have admin/power users who are creating and consuming without consideration for search-head resources it could cause issues for other users.

If you are able to, I would recommend installing the S.O.S. app. It's great for troubleshooting resource issues.
http://apps.splunk.com/app/748/

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...