Splunk Search

"The system is approaching the maximum number of historical searches" - how to fix/hide it?

bckq
Path Finder

Is there any way to hide that information from the top of splunk screen?
"The system is approaching the maximum number of historical searches
that can be run concurrently. current=47 maximum=54"

Will increasing limit in limits.conf affect on performance of Splunk?

I have CPU with 4 cores/8 threads and 24GB RAM.

kristian_kolb
Ultra Champion

Ooh, now I see that this post was rather old. Hope you've solved the problem already.

0 Karma

kristian_kolb
Ultra Champion

Well, changing the limits in limits.conf will change how Splunk will treat the search load. However, it will NOT magically upgrade the underlying hardware. So, while you may be able to tweak out some more performance by increasing limits, at some point it will actually get worse due to swapping etc etc.

I don't have any hard figures on how much you could possibly increase the limits, but there is nothing that will break permanently if you try to change it. Perhaps only some searches that will not be run on time (or at all). A restart after changing (and rolling back 🙂 is also required.

/K

linu1988
Champion

are all those real-time jobs?

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...