Splunk Search

mvexpand truncate result because of exceed 500MB memory usage

ahmedhassanean
Explorer

Dears,

i have splunk 6.3.3 and i am using query that have command mvexpand but mvexpand truncate result because of exceed 500MB memory usage i have found on splunk doc of version 5 that i can edit limits.conf value of max_memory_usage to higher value than 500MB but it's not working in version 6.3 and also this option not exist in default configuration of limits.conf

please advise

0 Karma

vasanthmss
Motivator

You need to increase the size in limits.conf or optimize your search like reduce the data size that needs to be processed by search intervals

V
0 Karma

somesoni2
SplunkTrust
SplunkTrust

In 6.3.3, the attribute that you're interested in is called max_mem_usage_mb.

ahmedhassanean
Explorer

yes it's the same as 5.0.3 but search query still truncate at 500 MB

0 Karma

vasanthmss
Motivator

What is the search interval you are running now? If possible share some sample data along with search

V
0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...