<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Dashboard Causing Browsers to crash? in Security</title>
    <link>https://community.splunk.com/t5/Security/Splunk-Dashboard-Causing-Browsers-to-crash/m-p/274054#M7400</link>
    <description>&lt;P&gt;Yes:&lt;/P&gt;

&lt;P&gt;1: upgrade to the latest version (there are big improvements in parallelization).&lt;BR /&gt;
2: stop using real-time searches (they probably are not working the way you expect anyway).&lt;/P&gt;</description>
    <pubDate>Mon, 04 Apr 2016 12:55:40 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2016-04-04T12:55:40Z</dc:date>
    <item>
      <title>Splunk Dashboard Causing Browsers to crash?</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Dashboard-Causing-Browsers-to-crash/m-p/274053#M7399</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;We have Splunk 6.2, and we have a dashboard that utilizes 9 real-time searches and 4 historical searches.  On both Chrome and Firefox, the dashboard causes the browser to crash intermittently throughout the day.&lt;/P&gt;

&lt;P&gt;Is there anything that can be done to alleviate this issue?  We'd like to keep the dashboard running throughout the day in our office, and this issue is preventing us from doing so.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
JB&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2016 12:27:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Dashboard-Causing-Browsers-to-crash/m-p/274053#M7399</guid>
      <dc:creator>butzowj</dc:creator>
      <dc:date>2016-04-04T12:27:15Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Dashboard Causing Browsers to crash?</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Dashboard-Causing-Browsers-to-crash/m-p/274054#M7400</link>
      <description>&lt;P&gt;Yes:&lt;/P&gt;

&lt;P&gt;1: upgrade to the latest version (there are big improvements in parallelization).&lt;BR /&gt;
2: stop using real-time searches (they probably are not working the way you expect anyway).&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2016 12:55:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Dashboard-Causing-Browsers-to-crash/m-p/274054#M7400</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2016-04-04T12:55:40Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Dashboard Causing Browsers to crash?</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Dashboard-Causing-Browsers-to-crash/m-p/274055#M7401</link>
      <description>&lt;P&gt;Can you explain what is meant by "they probably are not working the way you expect anyway"?&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2016 13:29:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Dashboard-Causing-Browsers-to-crash/m-p/274055#M7401</guid>
      <dc:creator>butzowj</dc:creator>
      <dc:date>2016-04-04T13:29:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Dashboard Causing Browsers to crash?</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Dashboard-Causing-Browsers-to-crash/m-p/274056#M7402</link>
      <description>&lt;P&gt;It is too varied but I would be happy to come in on a 1 day contract to explore it with you.  It may suffice to say that in all of my work with clients, I have never seen a real-time search implementation that was working as desired and in the end, as we explored the requirements, we always used something non-real-time that was more than good enough, so that we could avoid the calamitous downsides of real-time.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2016 14:09:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Dashboard-Causing-Browsers-to-crash/m-p/274056#M7402</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2016-04-04T14:09:39Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Dashboard Causing Browsers to crash?</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Dashboard-Causing-Browsers-to-crash/m-p/274057#M7403</link>
      <description>&lt;P&gt;The only way to "make real-time work" is to mis-timestamp your events, which obviously, most people are unwilling to do.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2016 14:12:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Dashboard-Causing-Browsers-to-crash/m-p/274057#M7403</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2016-04-04T14:12:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Dashboard Causing Browsers to crash?</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Dashboard-Causing-Browsers-to-crash/m-p/274058#M7404</link>
      <description>&lt;P&gt;I feel we would be better served to call this out as failures in design, not bad user behavior. Ideally, Splunk should NEVER cause the client to crash. &lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2016 14:55:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Dashboard-Causing-Browsers-to-crash/m-p/274058#M7404</guid>
      <dc:creator>halr9000</dc:creator>
      <dc:date>2016-04-04T14:55:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Dashboard Causing Browsers to crash?</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Dashboard-Causing-Browsers-to-crash/m-p/274059#M7405</link>
      <description>&lt;P&gt;A few things: &lt;/P&gt;

&lt;P&gt;1) You can force an automated refresh of the dashboard to help clear memory issues.&lt;BR /&gt;
2) Re-design your Searches. Splunk searches consume memory in the browser.  While not necessarily related to real-time, make sure that your searches are highly optimized. Ditch the real-time (as @woodcock mentions) and go with a historical search that only looks at the relevant time frame (last hour or so if that works for you).&lt;/P&gt;

&lt;P&gt;To force automatic dashboard refreshes, edit the dashboard XML, and add this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;dashboard refresh="300"&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This will auto refresh the dashboard every 5 minutes (300 seconds).&lt;/P&gt;

&lt;P&gt;There is also more information here: &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Search/Writebettersearches"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Search/Writebettersearches&lt;/A&gt; on how to start optimizing your searches for efficiency.&lt;/P&gt;

&lt;P&gt;Find us in IRC on efnet.org in #splunk, or join Slack (&lt;A href="http://www.splunk402.com/chat"&gt;www.splunk402.com/chat&lt;/A&gt;) and find us there as well for all of your questions!&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2016 14:59:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Dashboard-Causing-Browsers-to-crash/m-p/274059#M7405</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2016-04-04T14:59:32Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Dashboard Causing Browsers to crash?</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Dashboard-Causing-Browsers-to-crash/m-p/274060#M7406</link>
      <description>&lt;P&gt;This works for now - it may not be the best practices solution in the long term, but forcing the dashboard to refresh will definitely alleviate the crashes.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2016 15:02:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Dashboard-Causing-Browsers-to-crash/m-p/274060#M7406</guid>
      <dc:creator>butzowj</dc:creator>
      <dc:date>2016-04-04T15:02:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Dashboard Causing Browsers to crash?</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Dashboard-Causing-Browsers-to-crash/m-p/274061#M7407</link>
      <description>&lt;P&gt;When there is no more RAM, if ANY process running on the machine is not 100% bug free as regards memory-management, you will crash everything.  So the memory-management problem could be ANYWHERE (in any running process) but the precipitating factor causing all RAM to be used is the real-time search load.&lt;/P&gt;

&lt;P&gt;IMHO, if somebody has a legitimate &lt;CODE&gt;real-time&lt;/CODE&gt; requirement, then Splunk is the wrong tool for the job.&lt;/P&gt;

&lt;P&gt;This is because Splunk is "too literal" (this is a &lt;EM&gt;VERY&lt;/EM&gt; good thing) as regards &lt;CODE&gt;_time&lt;/CODE&gt; and because there is always latency everywhere in everything.  The only way to claim to be "real-time" is to gloss over all latencies and pretend that things happened later than they really did.  If Splunk had a &lt;CODE&gt;pseudo-real-time&lt;/CODE&gt; mode that worked on &lt;CODE&gt;_indextime&lt;/CODE&gt; then that would be something else entirely.  I do not like to tell my data to lie to me; and I don't help my clients to tell their data to lie to them, either.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2016 15:05:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Dashboard-Causing-Browsers-to-crash/m-p/274061#M7407</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2016-04-04T15:05:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Dashboard Causing Browsers to crash?</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Dashboard-Causing-Browsers-to-crash/m-p/274062#M7408</link>
      <description>&lt;P&gt;I downvoted this post because you are using answers to advertise your services. please don't do this in the future.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2016 17:56:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Dashboard-Causing-Browsers-to-crash/m-p/274062#M7408</guid>
      <dc:creator>piebob</dc:creator>
      <dc:date>2016-04-04T17:56:15Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Dashboard Causing Browsers to crash?</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Dashboard-Causing-Browsers-to-crash/m-p/274063#M7409</link>
      <description>&lt;P&gt;Would it have been "OK" to say something like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;You should see if you can hire a Splunk consultant for a couple of days to health-check your real-time searches because it is too complicated to go through in this forum
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I was NOT trying to sell my services (I am plenty busy) but I was trying to give him a viable option because I think his dashboard is probably a ticking time-bomb on multiple fronts and it is not practical to unwrap it here.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2016 18:18:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Dashboard-Causing-Browsers-to-crash/m-p/274063#M7409</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2016-04-04T18:18:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Dashboard Causing Browsers to crash?</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Dashboard-Causing-Browsers-to-crash/m-p/274064#M7410</link>
      <description>&lt;P&gt;that wording is definitely better. i appreciate your willingness to amend it. thanks. &lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2016 18:46:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Dashboard-Causing-Browsers-to-crash/m-p/274064#M7410</guid>
      <dc:creator>piebob</dc:creator>
      <dc:date>2016-04-04T18:46:15Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Dashboard Causing Browsers to crash?</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Dashboard-Causing-Browsers-to-crash/m-p/274065#M7411</link>
      <description>&lt;P&gt;This has been a known issue but recently splunkjs memory leak issue's been resolved and the fix is included in 6.4.5+ and 6.5.2+. Please try and provide any feedback.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2017 04:16:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Dashboard-Causing-Browsers-to-crash/m-p/274065#M7411</guid>
      <dc:creator>sylim_splunk</dc:creator>
      <dc:date>2017-01-09T04:16:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Dashboard Causing Browsers to crash?</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Dashboard-Causing-Browsers-to-crash/m-p/274066#M7412</link>
      <description>&lt;P&gt;The memory leak is still there, I just upgraded my entire environment (10 nodes) to 6.5.2 mainly because I wanted this fixed and they are still running out of memory.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2017 00:04:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Dashboard-Causing-Browsers-to-crash/m-p/274066#M7412</guid>
      <dc:creator>johnpof</dc:creator>
      <dc:date>2017-02-03T00:04:35Z</dc:date>
    </item>
  </channel>
</rss>

