Buon giorno Giuseppe, I have managed to make my Splunk status green by doing the following: 1. Fixing the default tags on Splunk CIM | rest splunk_server=remote* servicesNS/-/-/saved/eventtypes
| search tags=*
| table eai:acl.app, eai:acl.sharing eai:acl.perms.read, title, search, tags, author this search helped me identify which are the tags that I should whitelist in each datamodel. Indexes were already set in macros but tags seemed to be completely wrong. 2. Fixing my ulimits The fsize line was missing, which was the one that fixed my open files warning. * hard nofile 64000
* hard nproc 16000
* hard fsize -1 I have checked all my scheduled searches one by one and they were optimized (search window: auto, no real-time searches). 3. Minimized the summary indexing according to needs Some datamodels were set to create a summary index for a period that I did not need (eg. 1 year). So changing this to a smaller range might have helped too. Hardware resource consumption was and still seems to be in low levels, but an upgrade has to be performed for sure. Thanks a lot for your support. With kind regards, Chris
... View more