Splunk Enterprise

app and limits.conf

human96
Communicator

I want to control the number of concurrent user searches on an app-by-app basis.

I think it is possible to control the number of concurrent executions on a role-by-role basis, but is it possible to control on an app-by-app basis?

If control is possible on an app-by-app basis, please tell me how to control it.

(I think it is feasible by distributing limits.conf (base_max_searches) under App.)

0 Karma

tshah-splunk
Splunk Employee
Splunk Employee

Concurrent searches can be controlled using base_max_searches and max_searches_per_cpu. But those are global settings only as mentioned by @isoutamo It would be better to restrict the users based on roles and apply the limits globally. Creating roles based on apps can become a complex job for managing roles, current and future users, current and future apps as well. 

---
If you find the answer helpful, an upvote/karma is appreciated
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

Quite many attribute on limits.conf are global not local for app. Also this is global. At least I don’t know any easy way to do it. Basically you could create app based roles which have this value, but if user has many roles then he/she will get the highest value for all apps.

r. Ismo 

Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...