Splunk Enterprise Security

The dreadded does not meet the recommended minimum system requirement — but I do...So???

todd_r_martin21
Explorer

I have an Enterprise Security search head with 44 Physical Cores and 32GB RAM( reporting as 30.92GB) I am getting the message still even though the server meets the criteria.

Here is the search string for this check, found in savedsearchs.conf

search                               = | rest splunk_server=* count=0 /services/server/info
 | eval numberOfVirtualCores=if(isnum(numberOfVirtualCores) AND numberOfVirtualCores>0,numb
erOfVirtualCores,null()) | where ((server_roles="search_head" AND (max(numberOfCores,number
OfVirtualCores)<16 OR physicalMemoryMB<32000)) OR (server_roles="indexer" AND (max(numberOf
Cores,numberOfVirtualCores)<16 OR physicalMemoryMB<32000))) | fields + splunk_server,server
_roles,numberOfCores,numberOfVirtualCores,physicalMemoryMB

should i edit this to physicalMemoryMB<30000 to resolve this?

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...