Adjust the concurrent searches for a role
Splunk platform defines a limit on concurrently running searches for the user
and power
roles by default. You may want to change those concurrent searches for some roles.
- In Splunk Enterprise Security, select Configure.
- Select General and then select General settings.
- Review the limits for roles and change them as desired.
Item | Description |
---|---|
Search disk quota (admin) | The maximum disk space (MB) a user with the admin role can use to store search job results. |
Search jobs quota (admin) | The maximum number of concurrent searches for users with the admin role. |
Search jobs quota (power) | The maximum number of concurrent searches for users with the power role. |
To change the limits for roles other then admin
and power
, edit the authorize.conf
file to update the default search quota. See the authorize.conf.example in the Splunk Enterprise Admin manual.