Adjust the concurrent searches for a role

Splunk platform defines a limit on concurrently running searches for the user and power roles by default. You may want to change those concurrent searches for some roles.

  1. In Splunk Enterprise Security, select Configure.
  2. Select General and then select General settings.
  3. Review the limits for roles and change them as desired.
Item Description
Search disk quota (admin) The maximum disk space (MB) a user with the admin role can use to store search job results.
Search jobs quota (admin) The maximum number of concurrent searches for users with the admin role.
Search jobs quota (power) The maximum number of concurrent searches for users with the power role.

To change the limits for roles other then admin and power, edit the authorize.conf file to update the default search quota. See the authorize.conf.example in the Splunk Enterprise Admin manual.