<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is there a big difference in performance of searches run admin vs splunk system users? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-is-there-a-big-difference-in-performance-of-searches-run/m-p/341805#M101274</link>
    <description>&lt;P&gt;It looks like you are not comparing the same searches. The splunk-system-user account is used internally by Splunk to accomplish a lot of background work, so it is doing a lot of searches (and possibly alerts) that are more complex than most user searches.&lt;/P&gt;

&lt;P&gt;Ad-hoc searches run by users, typically using the Splunk GUI, have a higher priority than background or scheduled searches. They are also typically less complex.&lt;/P&gt;

&lt;P&gt;If this doesn't answer the question, then can you post a specific search that was run by both users, and give the execution time statistics for both searches?&lt;/P&gt;</description>
    <pubDate>Thu, 01 Feb 2018 07:37:00 GMT</pubDate>
    <dc:creator>lguinn2</dc:creator>
    <dc:date>2018-02-01T07:37:00Z</dc:date>
    <item>
      <title>Why is there a big difference in performance of searches run admin vs splunk system users?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-there-a-big-difference-in-performance-of-searches-run/m-p/341804#M101273</link>
      <description>&lt;P&gt;I have been investigating into searches for both admin user and splunk system user. Searched conducted by System User takes very long time. Searches done by system user are typically bucket copy trigger, copy buckets, summarize etc. Can someone explain why there is such a big difference:&lt;/P&gt;

&lt;P&gt;Search Activity by User (2)&lt;BR /&gt;
User    Search Count    Median Runtime  90th Percentile Runtime Cumulative Runtime  Last Search&lt;BR /&gt;
1   admin   201 0.17s   0.46s   5h 32min 13.32s 2018-01-31 09:55:39&lt;BR /&gt;
2   splunk-system-user  150 3.58s   10.00s  13min 42.47s    2018-01-31 09:47:14&lt;/P&gt;

&lt;P&gt;Common Search Commands (first there are for Splunk System user)&lt;BR /&gt;
Command Count   Average Runtime Max Runtime&lt;BR /&gt;
1   summarize   100 3.86s   20.25s&lt;BR /&gt;
2   bucket  25  9.56s   26.89s&lt;BR /&gt;
3   copybuckets 25  7.92s   21.65s&lt;BR /&gt;
4   kv  4   0.06s   0.12s&lt;BR /&gt;
5   metadata    2   1.23s   1.41s&lt;BR /&gt;
6   search  2   1.23s   1.41s&lt;/P&gt;

&lt;P&gt;Appreciate your response.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;

&lt;P&gt;Anup Pal&lt;BR /&gt;
Solution Engineer,&lt;BR /&gt;
SwiftStack Inc.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2018 18:07:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-there-a-big-difference-in-performance-of-searches-run/m-p/341804#M101273</guid>
      <dc:creator>anupkpal</dc:creator>
      <dc:date>2018-01-31T18:07:41Z</dc:date>
    </item>
    <item>
      <title>Re: Why is there a big difference in performance of searches run admin vs splunk system users?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-there-a-big-difference-in-performance-of-searches-run/m-p/341805#M101274</link>
      <description>&lt;P&gt;It looks like you are not comparing the same searches. The splunk-system-user account is used internally by Splunk to accomplish a lot of background work, so it is doing a lot of searches (and possibly alerts) that are more complex than most user searches.&lt;/P&gt;

&lt;P&gt;Ad-hoc searches run by users, typically using the Splunk GUI, have a higher priority than background or scheduled searches. They are also typically less complex.&lt;/P&gt;

&lt;P&gt;If this doesn't answer the question, then can you post a specific search that was run by both users, and give the execution time statistics for both searches?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2018 07:37:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-there-a-big-difference-in-performance-of-searches-run/m-p/341805#M101274</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2018-02-01T07:37:00Z</dc:date>
    </item>
  </channel>
</rss>

