Getting Data In

What is the impact of increasing indexed_kv_limit in limits.conf?

mufthmu
Path Finder

Hi,

Some of my data has 1000+ fields and I want to increase indexed_kv_limit value to 2000 from limits.conf .

I know it's a big increase since the default value is only 200. I want to know how this activity can impact my indexing or search performance?

Thanks!

Labels (1)
0 Karma

somesoni2
Revered Legend

I believe it'll cause additional disk usage (as more indexed fields will be stored in tsidx files) and slightly slower indexing rate (more fields to be extracted and stored). Searching would be faster if you're searching on those indexed field.

0 Karma
Get Updates on the Splunk Community!

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...