Splunk Search

Search is queued: The maximum number of historical concurrent system-wide searches has been reached. current=11 maximum=10 Search not executed!

wudu0517
New Member

I'm in search of the above tips on how to solve?

Tags (1)
0 Karma

wudu0517
New Member

Splunk 5.0.1 ,

limit.conf
[subsearch]
maxout=10000
maxtime = 1800

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

What version of Splunk? Did you change anything in limits.conf?

0 Karma

wudu0517
New Member

Splunk Search Head 2 CPU 8 core, 8G memory

0 Karma

fengjie
New Member

I try, thank you very much!

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

How many CPU and How Much RAM does your Search Head have?

0 Karma

jtrucks
Splunk Employee
Splunk Employee

Go to Manage -> Access controls -> Roles. I suspect you are a Power user (or other role with similar job limit settings), so either create a new role or edit Power to increase "Limit concurrent search jobs" to a higher number.

--
Jesse Trucks
Minister of Magic

linu1988
Champion

It depends on the role of the user and maximum number of searches allowed to that use. You can see them in access control->roles->Role_Name if you are an ADMIN. There you can modify the number of searched availed to the role, which the user belong to. Thanks.

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...