Splunk Search

Ulimit for open files did not match

Splunk Employee
Splunk Employee


I have increased our ulimit for open file in our indexer to 65536 as recommended by splunk support. After the change, I checked the ulimit -n value in server and got the 65536 value as intended. However when I run health check using GUI, I got a warning saying that my ulimit for open file is still 4096.

Hence, I want to know if this a bug or is there something else that I am missing?

Tags (1)
0 Karma

Esteemed Legend

The easiest way to ensure that Splunk has the ulimit setting that you need, is to enable boot-start and NOT use systemd. Then make sure that the top of /etc/init.d/splunk looks like this:

# /etc/init.d/splunk
# init script for Splunk.
# generated by 'splunk enable boot-start'.
# chkconfig: 2345 90 60
# description: Splunk indexer service

. /etc/init.d/functions
ulimit -Hn 65536
ulimit -Sn 32768
ulimit -u 16384
0 Karma

Splunk Employee
Splunk Employee

Please check first which OS version you are running. If it is Redhat 7 then changes should be at systemd level.


Earlier, I believe you have made the changes as per the process mentioned for below 7 version.

0 Karma
Get Updates on the Splunk Community!

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...

Ready, Set, SOAR: How Utility Apps Can Up Level Your Playbooks!

 WATCH NOW Powering your capabilities has never been so easy with ready-made Splunk® SOAR Utility Apps. Parse ...