Splunk Search

The maximum number of concurrent historical searches on this instance has been reached. 26/11/2020, 11:08:15

roderick001
Explorer

Hello, I am stuck, this error message keeps appearing, so I cannot run any searches, they just get queued up.

It has rendered my Splunk instance as unusable? 

 

I was thinking I may have too many searches running in the background due to tutorial zip files loaded? I cannot delete the tutorial files as  cannot run any searches?

 

And does this also stop me from seeing csv and zip files I have recently successfully uploaded, as I cannot see them??

Any help would be great, thanks a lot.

Labels (1)
Tags (2)
1 Solution

isoutamo
SplunkTrust
SplunkTrust
This is just an informative message, that in sometime earlier there has been running as many jos as it can run at a time. Just delete it and if it's happened regularly then it's time to look why this is happening.

View solution in original post

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Probably there are some report, alerts or data model acceleration or report acceleration defined. Go to Alerts tab and disable unneeded alerts., then same for reports.
Basically you should see those via MC - Search - Scheduler.
r. Ismo
0 Karma

roderick001
Explorer

Hi,  @isoutamo  @impurush I cannot even run my monitoring console as the reports are all being queued.

But I cannot see any alerts in searches reports and alerts, and I also don't have an Administrator button.

I have attached a screenshot of the reports that are being run. I deleted these yesterday but they are back up and running today, very confusing as I am not running them.

 

Thanks a lot for your help.

 

roderick001_0-1606480129912.png

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Please change app to All from MC when you are looking which job there are running. Also owner etc. should be All.

0 Karma

roderick001
Explorer

Hi @isoutamo  I have selected all the reports in activity and have stopped all of them, but when I return to search app the error occurs again and all the reports show up again. So effectively I cannot use my Splunk instance. Does it need a re-install? Thanks.

0 Karma

isoutamo
SplunkTrust
SplunkTrust
When those are scheduled (etc.) it didn't help to just stop on activity screen (only for short period). And in your attached picture it's showing only jobs which are launch under app MC and seems to be a Waiting status. So there must be a lot of other jobs under other applications (for that reason select All instead of Monitoring Console for application). Then you can see what those jobs are and where you should disable those.
0 Karma

roderick001
Explorer

Hi @isoutamo  here is a screenshot of all selected, no jobs running, but when I go to the search and reporting app the error message occurs again.

 

roderick001_0-1606482781351.png

 

 

 

 

0 Karma

roderick001
Explorer

@isoutamo 

roderick001_0-1606483414492.png

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust
This is just an informative message, that in sometime earlier there has been running as many jos as it can run at a time. Just delete it and if it's happened regularly then it's time to look why this is happening.
0 Karma

roderick001
Explorer

Hi @isoutamo , thanks, @impurush  thanks too, I have updated my Splunk install, and error message is not showing anymore, so great thanks for your help. My search capability is back which is great.

Also now I am having trouble adding any csv data or zip data, I am only seeing csv files by adding by lookup, 

when I add the file in ADD DATA the file uploads successfully but I cannot see it?

Thanks a lot for any help.

0 Karma

impurush
Contributor

Hi @roderick001 ,

You can see the job/search status under the Activity->Jobs tab and see what is running, then you can take necessary action whether to stop/pause.

Which Splunk version are you using? If you are installed or updated recently to 8.0.x version and if you are not able to view the lookup page, then one of your dashboard is without a title. This is a known issue.

0 Karma

roderick001
Explorer

Hi, thanks, checked Activity jobs, I am logged in as Admin and not my username, as Admin there are quite a few searches going on which I am not running.

I am running Splunk 8.0.6 Enterprise free, and I cannot see the login or logout button, how do I log out and run Splunk with my username, it keeps booting up as Admin?

Thanks for your help.

@impurush 

0 Karma

impurush
Contributor

@roderick001 If you can paste the screenshot of what type of jobs you are running, that will be helpful.

Hope the Splunk is running by you alone or your team?

By the way, the logout option will be under your username(Admin).

impurush_0-1606421767262.png

 

0 Karma
Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...