Splunk Search

StatsBuffer::read: Row is too large for StatsBuffer, resizing buffer

joemcmahon
Explorer

When performing a query that creates a summary report, the associated search.log file shows:
ResultsCollationProcessor - writing remote_event_providers.csv to disk.

Then two hours later reports:

StatsBuffer::read: Row is too large for StatsBuffer, resizing buffer.  row_size=77060 needed_space=11536 free_space=153653063

This is soon followed by lots of ~min-by-min output of:

SummaryIndexProcessor - Using tmp_file=/opt/splunk/..../RMD....tmp messages.

What might be happening in that two hour window?  We are running Splunk Enterprise 9.1.1 under Linux.

@koronb_splunk @C_Mooney 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

What's New in Splunk Cloud Platform 9.3.2411?

Hey Splunky People! We are excited to share the latest updates in Splunk Cloud Platform 9.3.2411. This release ...

Buttercup Games: Further Dashboarding Techniques (Part 6)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...