Splunk Search

Search is queued: The maximum number of historical concurrent system-wide searches has been reached. current=11 maximum=10 Search not executed!

wudu0517
New Member

I'm in search of the above tips on how to solve?

Tags (1)
0 Karma

wudu0517
New Member

Splunk 5.0.1 ,

limit.conf
[subsearch]
maxout=10000
maxtime = 1800

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

What version of Splunk? Did you change anything in limits.conf?

0 Karma

wudu0517
New Member

Splunk Search Head 2 CPU 8 core, 8G memory

0 Karma

fengjie
New Member

I try, thank you very much!

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

How many CPU and How Much RAM does your Search Head have?

0 Karma

jtrucks
Splunk Employee
Splunk Employee

Go to Manage -> Access controls -> Roles. I suspect you are a Power user (or other role with similar job limit settings), so either create a new role or edit Power to increase "Limit concurrent search jobs" to a higher number.

--
Jesse Trucks
Minister of Magic

linu1988
Champion

It depends on the role of the user and maximum number of searches allowed to that use. You can see them in access control->roles->Role_Name if you are an ADMIN. There you can modify the number of searched availed to the role, which the user belong to. Thanks.

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...