ES app creating large lookup file the size nearly 600MB file. So as the work around suggested from Splunk docs we increased max_memtable_bytes value to 700MB in limits.conf on all the indexers. After the change search heads working very slow and searches aso working slow.
Does this change have any impact on search heads??
↧