Splunk Search

mvexpand truncate result because of exceed 500MB memory usage

ahmedhassanean
Explorer

Dears,

i have splunk 6.3.3 and i am using query that have command mvexpand but mvexpand truncate result because of exceed 500MB memory usage i have found on splunk doc of version 5 that i can edit limits.conf value of max_memory_usage to higher value than 500MB but it's not working in version 6.3 and also this option not exist in default configuration of limits.conf

please advise

0 Karma

vasanthmss
Motivator

You need to increase the size in limits.conf or optimize your search like reduce the data size that needs to be processed by search intervals

V
0 Karma

somesoni2
SplunkTrust
SplunkTrust

In 6.3.3, the attribute that you're interested in is called max_mem_usage_mb.

ahmedhassanean
Explorer

yes it's the same as 5.0.3 but search query still truncate at 500 MB

0 Karma

vasanthmss
Motivator

What is the search interval you are running now? If possible share some sample data along with search

V
0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...