I do have Search head with 16 cores & 2Gb RAM Memory , using Splunk 5.x
As , per the calculation for Concurrent search , My system wide Concurrent search is 22
max_hist_searches = max_searches_per_cpu x number_of_cpus + base_max_searches
max_hist_searches = 1 x 16 + 6 => 16 + 6 => 22
22 is the maximum number of concurrent search that my search hear can handle.
I do see for 'admin' role the values are as below :
Limit concurrent search jobs = 50
Limit concurrent real-time search jobs =100
These values are present by default in the Splunk web under authrorize.conf file.
How does the maximum concurrent search jobs limit can be 50 , when the system wide range itself 22 ?
Also , if I do specify the a count greater than the system wide limit does Splunk overrides the value within the allowed range ?
In this case , how do other users are affected , when 'admin' user takes the full control when he has maximum concurrent search limit ?
I am confused in this. Please advise on how to limit the users on concurrent search , considering the system wide limit.
... View more