Search restrictions
In the search restrictions section, you can manage settings to restrict search terms, time ranges, and a number of values for user-level and role-level concurrent real-time and adhoc or saved-search (from reports, for example) search jobs, as well as a total jobs disk-usage quota. Since each concurrent search consumes a CPU core on a search head, as well as consuming CPU on indexers, you may need to reduce the allowed number of concurrent searches as your user population grows, although you really should just increase the number of search heads and indexers if the search load is legitimate. When users begin to hit the concurrent search limits, they will receive Splunk warnings to this effect, and if the problem gets bad ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access