Products/Services
product
service
- Simple Security Consulting [Consulting]
- Splunk SOAR Automation Assessment Service [Consulting]
- Dashboard/SPL Creation Pack [Implementation/Building Support]
- Version upgrade service [implementation and construction support]
- Splunk Premium Apps construction support service [implementation and construction support]
- Splunk Security Log Analysis Start Package [Original App/Service]
- Splunk × CrowdStrike Falcon Insight, Macnica Original App [Original App/Service]
- Government uniform standard compatible App [Original App/Service]
- Smart Security Monitoring App [Original App/Service]
- Splunk × LANSCOPE Original App [Original App/Service]
- Security Monitoring App for Box [Original App/Service]
- Cloud Security Monitoring App [Original App/Service]
- SIEM Operation Monitoring Service [Original App/Service]
- List of services
- Macnica Premium Support for Splunk (utilization support, version upgrade monitoring)
- Macnica Premium Support for Splunk Skill Up Package
Specifications/Technical Information
Specifications/Technical Information
Evaluation machine application/FAQ
Application for evaluation machine
- FAQ
How to limit concurrent search executions by user or role
- release date
- 2018-06-18
- last updated
- 2024-01-11
- version
- Splunk Enterprise 9.0.3
- Overview
- Limit concurrent search runs per user or role
- Reference information
- content
-
In Splunk settings, it is possible to limit the maximum number of concurrent search jobs and concurrent real-time searches for each user, as well as the maximum number of concurrent search jobs and total concurrent real-time searches for each role.
Setting method
- Log in to Splunk Web as a user with admin privileges, go to "Settings" > "Roles", click the role name you want to configure, and change the following values in the "5. Resources" tab.
- Role-level concurrent search job limit
- Role-level concurrent real-time search job limit
- User-level concurrent search job limit
- User-level concurrent real-time search job limit
- Add the following to the configuration file to enable role-level job limit settings:
$SPLUNK_HOME/etc/system/local/limits.conf
[search]enable_cumulative_quota = true*$SPLUNK_HOME is the installation directory. By default, it is as follows:
Linux: /opt/splunk
Windows: C:\Program Files\Splunk- Restart the Splunk service to reflect the settings in 2 above.
that's all
In charge of Macnica Splunk Co., Ltd.
- TEL:045-476-2010
- E-mail:splunk-sales@macnica.co.jp
Mon-Fri 8:45-17:30