<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Different search performance for two sourcetype in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Different-search-performance-for-two-sourcetype/m-p/112854#M23641</link>
    <description>&lt;P&gt;Hi pradeepchhetri,&lt;/P&gt;

&lt;P&gt;This is the kind of question, that is almost impossible for anyone to answer, except to you - because you know your setup, know your events, know your server's load and so on.....&lt;/P&gt;

&lt;P&gt;here are some basic troubleshooting things:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;do both sourcetypes have exactly the same event count over the exact same time range?&lt;/LI&gt;
&lt;LI&gt;is your search head / indexer over loaded?&lt;/LI&gt;
&lt;LI&gt;are there any saved searches running?&lt;/LI&gt;
&lt;LI&gt;check the job inspector to get any idea why one search is running slower as the other.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;you see, there is a lot to check for you.&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
    <pubDate>Fri, 20 Jun 2014 11:22:29 GMT</pubDate>
    <dc:creator>MuS</dc:creator>
    <dc:date>2014-06-20T11:22:29Z</dc:date>
    <item>
      <title>Different search performance for two sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Different-search-performance-for-two-sourcetype/m-p/112851#M23638</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;We have a splunk machine running with all the events going to one index. I noticed that for two different sourcetype, I got different search performance. For one of the sourcetype, searching happened very quickly but it was very slow for the other. Can someone explain me why i am getting such a difference.&lt;/P&gt;

&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jun 2014 09:21:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Different-search-performance-for-two-sourcetype/m-p/112851#M23638</guid>
      <dc:creator>pradeepchhetri</dc:creator>
      <dc:date>2014-06-20T09:21:21Z</dc:date>
    </item>
    <item>
      <title>Re: Different search performance for two sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Different-search-performance-for-two-sourcetype/m-p/112852#M23639</link>
      <description>&lt;P&gt;Can you post your search query ?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jun 2014 09:43:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Different-search-performance-for-two-sourcetype/m-p/112852#M23639</guid>
      <dc:creator>splunker12er</dc:creator>
      <dc:date>2014-06-20T09:43:17Z</dc:date>
    </item>
    <item>
      <title>Re: Different search performance for two sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Different-search-performance-for-two-sourcetype/m-p/112853#M23640</link>
      <description>&lt;P&gt;my search query just includes: sourcetype="production" and sourcetype="staging"&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jun 2014 09:59:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Different-search-performance-for-two-sourcetype/m-p/112853#M23640</guid>
      <dc:creator>pradeepchhetri</dc:creator>
      <dc:date>2014-06-20T09:59:16Z</dc:date>
    </item>
    <item>
      <title>Re: Different search performance for two sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Different-search-performance-for-two-sourcetype/m-p/112854#M23641</link>
      <description>&lt;P&gt;Hi pradeepchhetri,&lt;/P&gt;

&lt;P&gt;This is the kind of question, that is almost impossible for anyone to answer, except to you - because you know your setup, know your events, know your server's load and so on.....&lt;/P&gt;

&lt;P&gt;here are some basic troubleshooting things:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;do both sourcetypes have exactly the same event count over the exact same time range?&lt;/LI&gt;
&lt;LI&gt;is your search head / indexer over loaded?&lt;/LI&gt;
&lt;LI&gt;are there any saved searches running?&lt;/LI&gt;
&lt;LI&gt;check the job inspector to get any idea why one search is running slower as the other.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;you see, there is a lot to check for you.&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jun 2014 11:22:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Different-search-performance-for-two-sourcetype/m-p/112854#M23641</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-06-20T11:22:29Z</dc:date>
    </item>
    <item>
      <title>Re: Different search performance for two sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Different-search-performance-for-two-sourcetype/m-p/112855#M23642</link>
      <description>&lt;P&gt;@Mus: Thank you for the reply. I will do the troubleshooting accordingly and let you know the outcome.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jun 2014 12:01:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Different-search-performance-for-two-sourcetype/m-p/112855#M23642</guid>
      <dc:creator>pradeepchhetri</dc:creator>
      <dc:date>2014-06-20T12:01:03Z</dc:date>
    </item>
    <item>
      <title>Re: Different search performance for two sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Different-search-performance-for-two-sourcetype/m-p/112856#M23643</link>
      <description>&lt;P&gt;I'm going to guess that &lt;CODE&gt;production&lt;/CODE&gt; will have much more data than &lt;CODE&gt;staging&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jun 2014 14:43:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Different-search-performance-for-two-sourcetype/m-p/112856#M23643</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-06-20T14:43:25Z</dc:date>
    </item>
    <item>
      <title>Re: Different search performance for two sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Different-search-performance-for-two-sourcetype/m-p/112857#M23644</link>
      <description>&lt;P&gt;@Mus: @martin_mueller: Just realized that the difference was due to fast-mode and smart-mode search types, although both has same number of events. Thank you for the help.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jun 2014 06:48:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Different-search-performance-for-two-sourcetype/m-p/112857#M23644</guid>
      <dc:creator>pradeepchhetri</dc:creator>
      <dc:date>2014-06-23T06:48:28Z</dc:date>
    </item>
  </channel>
</rss>

