Splunk Search

mvexpand truncate result because of exceed 500MB memory usage

ahmedhassanean
Explorer

Dears,

i have splunk 6.3.3 and i am using query that have command mvexpand but mvexpand truncate result because of exceed 500MB memory usage i have found on splunk doc of version 5 that i can edit limits.conf value of max_memory_usage to higher value than 500MB but it's not working in version 6.3 and also this option not exist in default configuration of limits.conf

please advise

0 Karma

vasanthmss
Motivator

You need to increase the size in limits.conf or optimize your search like reduce the data size that needs to be processed by search intervals

V
0 Karma

somesoni2
Revered Legend

In 6.3.3, the attribute that you're interested in is called max_mem_usage_mb.

ahmedhassanean
Explorer

yes it's the same as 5.0.3 but search query still truncate at 500 MB

0 Karma

vasanthmss
Motivator

What is the search interval you are running now? If possible share some sample data along with search

V
0 Karma
Get Updates on the Splunk Community!

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...