Splunk Search

Maximum number of historical searches reached

sc0tt
Builder

I continually receive the error that I have reached the maximum number of historical searches (current=16 maximum=16). When I check the job monitor I usually only see 2-4 running; 2 of which are real-time searches.

How can I determine which searches are running and causing this error?

0 Karma
1 Solution

yannK
Splunk Employee
Splunk Employee

Install the SOS app and look at the search activity dashboards.
Then compare the had hoc and scheduled searches.

http://apps.splunk.com/app/748/

View solution in original post

yannK
Splunk Employee
Splunk Employee

Install the SOS app and look at the search activity dashboards.
Then compare the had hoc and scheduled searches.

http://apps.splunk.com/app/748/

sc0tt
Builder

Thanks, this was very helpful.

0 Karma