Splunk Search

Why is the Memory Tracker not working as expected?

dvg06
Path Finder

Hi Splunkers,

We have set search_process_memory_usage_threshold to 3GB, but noticed that searches are terminated when the usage reaches much higher values, example below.
Is this expected behaviour, or is there any other parameter to be enabled make it work better?

09-13-2018 10:59:00.013 +1000 WARN  SearchProcessMemoryTracker - Dispatch Command: The search processs with sid=XXXX was forcefully terminated because its physical memory usage (5626.160000 MB) has exceeded the 'search_process_memory_usage_threshold' (3000.000000 MB) setting in limits.conf.
0 Karma
1 Solution

traxxasbreaker
Communicator

Most likely the search's memory passed the threshold very quickly in between memory tracker doing its periodic checks. At a glance of the available limits.conf settings, I don't see anything that would let you tune the polling interval of memory tracker.

View solution in original post

0 Karma

dvg06
Path Finder

Thanks traxxasbreaker

0 Karma

traxxasbreaker
Communicator

Most likely the search's memory passed the threshold very quickly in between memory tracker doing its periodic checks. At a glance of the available limits.conf settings, I don't see anything that would let you tune the polling interval of memory tracker.

0 Karma

dvg06
Path Finder

thanks @traxxasbreaker.

Do we get an option to configure this period for checks?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...