Splunk Search

"The system is approaching the maximum number of historical searches" - how to fix/hide it?

bckq
Path Finder

Is there any way to hide that information from the top of splunk screen?
"The system is approaching the maximum number of historical searches
that can be run concurrently. current=47 maximum=54"

Will increasing limit in limits.conf affect on performance of Splunk?

I have CPU with 4 cores/8 threads and 24GB RAM.

kristian_kolb
Ultra Champion

Ooh, now I see that this post was rather old. Hope you've solved the problem already.

0 Karma

kristian_kolb
Ultra Champion

Well, changing the limits in limits.conf will change how Splunk will treat the search load. However, it will NOT magically upgrade the underlying hardware. So, while you may be able to tweak out some more performance by increasing limits, at some point it will actually get worse due to swapping etc etc.

I don't have any hard figures on how much you could possibly increase the limits, but there is nothing that will break permanently if you try to change it. Perhaps only some searches that will not be run on time (or at all). A restart after changing (and rolling back 🙂 is also required.

/K

linu1988
Champion

are all those real-time jobs?

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...