Splunk Search

mvexpand truncate result because of exceed 500MB memory usage

ahmedhassanean
Explorer

Dears,

i have splunk 6.3.3 and i am using query that have command mvexpand but mvexpand truncate result because of exceed 500MB memory usage i have found on splunk doc of version 5 that i can edit limits.conf value of max_memory_usage to higher value than 500MB but it's not working in version 6.3 and also this option not exist in default configuration of limits.conf

please advise

0 Karma

vasanthmss
Motivator

You need to increase the size in limits.conf or optimize your search like reduce the data size that needs to be processed by search intervals

V
0 Karma

somesoni2
Revered Legend

In 6.3.3, the attribute that you're interested in is called max_mem_usage_mb.

ahmedhassanean
Explorer

yes it's the same as 5.0.3 but search query still truncate at 500 MB

0 Karma

vasanthmss
Motivator

What is the search interval you are running now? If possible share some sample data along with search

V
0 Karma
Get Updates on the Splunk Community!

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...

Stay Connected: Your Guide to February Tech Talks, Office Hours, and Webinars!

💌Keep the new year’s momentum going with our February lineup of Community Office Hours, Tech Talks, ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...