Splunk Search

Splunk error

a212830
Champion

Hi,

I noticed a whole bunch of these in my S.O.S. Not sure what they mean - the filesystems are fine. Is somebody running too many searches?

3:12:00.325 PM

09-18-2012 15:12:00.325 -0400 ERROR SearchScheduler - Your maximum disk usage quota has been reached. usage=536MB quota=500MB user=a515330

Tags (2)
1 Solution

mixolydian
Path Finder

Pretty sure that means that the user under which the search is being run has exceeded the disk usage quota. You should figure out which user runs the search in question. You could increase the usage quota for that user's role, or run the search as a different user.

View solution in original post

mixolydian
Path Finder

Pretty sure that means that the user under which the search is being run has exceeded the disk usage quota. You should figure out which user runs the search in question. You could increase the usage quota for that user's role, or run the search as a different user.

a212830
Champion

Found it. Big search! Thanks.

mixolydian
Path Finder

Manager > Access controls > Roles

Each Role has a setting called "Limit total jobs disk quota". Perhaps the user in question (a515330) belongs to a role that has this set to 500 MB?

a212830
Champion

A disk quota within Splunk? I've never heard of this before - where is it configured?

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk Asynchronous Forwarding Explained

Splunk asynchronous forwarding is often misunderstood as simply setting autoLBVolume. That is not quite right. ...

55 Days to Go: Secure Your Seat at Splunk University in Denver

Your .conf26 Experience Starts Before Opening Keynote  If Denver is known for its mile-high elevation, Splunk ...

(re)Introducing the Splunk Community Champions + 2026 – 2027 Splunk MVPs ...

This program exists as a channel to empower and recognize Splunk advocates and help supercharge initiatives to ...