<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to troubleshoot why startup.handoff in the Search Job Inspector always seems to take a long time? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-troubleshoot-why-startup-handoff-in-the-Search-Job/m-p/525395#M148260</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is it possible that splunk changed the way how it calculates the search time? I have searches with "152,98 startup.handoff" and "This search has completed and ... in 2.272 seconds. " so without putting the huge handoff time in there. Looks like benchmark cheating &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Arnim&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 19 Oct 2020 15:25:46 GMT</pubDate>
    <dc:creator>Administrator</dc:creator>
    <dc:date>2020-10-19T15:25:46Z</dc:date>
    <item>
      <title>How to troubleshoot why startup.handoff in the Search Job Inspector always seems to take a long time?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-troubleshoot-why-startup-handoff-in-the-Search-Job/m-p/163244#M46312</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;

&lt;P&gt;I am running Splunk 6.2.2 on a distributed setup with 3 search heads in a search head cluster and 4 non-clustered indexers. Splunk seems sluggish and I am trying to figure out why &lt;CODE&gt;startup.handoff&lt;/CODE&gt; always seem to take a long time. For example:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;This search has completed and has returned 595 results by scanning 806 events in 6.179 seconds. 

Duration (seconds)      Component   Invocations     Input count     Output count
    0.01    command.fields  14  595     595
    0.02    command.remotetl    14  595     -
    0.26    command.search  14  -   595
    0.02    command.search.fieldalias   8   806     806
    0.02    command.search.calcfields   8   806     806
    0.01    command.search.index    14  -   -
    0.01    command.search.filter   8   -   -
    0.00    command.search.index.usec_1_8   1,431   -   -
    0.00    command.search.index.usec_8_64  25  -   -
    0.08    command.search.rawdata  8   -   -
    0.07    command.search.kv   8   -   -
    0.05    command.search.typer    8   595     595
    0.03    command.search.lookups  8   806     806
    0.01    command.search.tags     8   595     595
    0.00    command.search.summary  14  -   -
    0.00    dispatch.check_disk_usage   1   -   -
    0.12    dispatch.createdSearchResultInfrastructure  1   -   -
    1.00    dispatch.evaluate   1   -   -
    1.00    dispatch.evaluate.search    1   -   -
    0.28    dispatch.fetch  15  -   -
    1.04    dispatch.finalizeRemoteTimeline     1   -   -
    0.00    dispatch.localSearch    1   -   -
    0.01    dispatch.parserThread   13  -   -
    0.02    dispatch.process_remote_timeline    2   109,035     -
    0.17    dispatch.readEventsInResults    1   -   -
    0.04    dispatch.remote_timeline_fullevents     7   673,420     363
    0.00    dispatch.stream.local   1   -   -
    0.28    dispatch.stream.remote  13  -   869,624
    0.08    dispatch.stream.remote.SPLUNKIDX06  3   -   259,267
    0.07    dispatch.stream.remote.SPLUNKIDX05  3   -   263,521
    0.07    dispatch.stream.remote.SPLUNKIDX04  3   -   190,198
    0.06    dispatch.stream.remote.SPLUNKIDX03  3   -   152,511
    0.06    dispatch.timeline   15  -   -
    0.03    dispatch.writeStatus    8   -   -
    0.17    startup.configuration   6   -   -
    6.40    startup.handoff     6   -   -
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Any good tips where to look for the problem?&lt;/P&gt;

&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jun 2015 11:23:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-troubleshoot-why-startup-handoff-in-the-Search-Job/m-p/163244#M46312</guid>
      <dc:creator>gustavomichels</dc:creator>
      <dc:date>2015-06-22T11:23:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why startup.handoff in the Search Job Inspector always seems to take a long time?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-troubleshoot-why-startup-handoff-in-the-Search-Job/m-p/163245#M46313</link>
      <description>&lt;P&gt;Check the search.log linked to from the job inspector, scroll through it for gaps greater than a second in the timestamps.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2015 07:53:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-troubleshoot-why-startup-handoff-in-the-Search-Job/m-p/163245#M46313</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2015-06-25T07:53:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why startup.handoff in the Search Job Inspector always seems to take a long time?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-troubleshoot-why-startup-handoff-in-the-Search-Job/m-p/163246#M46314</link>
      <description>&lt;P&gt;Thanks for your reply. I don't get anything over 1 second, the closest is stuff like:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;06-25-2015 21:23:56.002 INFO  DispatchThread - Generating results preview took 2 ms
06-25-2015 21:23:56.844 INFO  NewTransam - Finalizing. Committing all open txns withheld

06-25-2015 21:30:12.649 INFO  DispatchThread - Generating results preview took 5 ms
06-25-2015 21:30:13.527 INFO  NewTransam - Finalizing. Committing all open txns withheld
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Remaining events are very close, the max gap I can find is 0.2/0.3 seconds for a handful, most are milliseconds apart.&lt;/P&gt;

&lt;P&gt;I don't get why search total times are lower than the time in &lt;CODE&gt;startup.handoff&lt;/CODE&gt;, like:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;This search has completed and has returned 49 results by scanning 24,453 events in 4.975 seconds.
8.03     startup.handoff
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2015 21:36:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-troubleshoot-why-startup-handoff-in-the-Search-Job/m-p/163246#M46314</guid>
      <dc:creator>gustavomichels</dc:creator>
      <dc:date>2015-06-25T21:36:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why startup.handoff in the Search Job Inspector always seems to take a long time?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-troubleshoot-why-startup-handoff-in-the-Search-Job/m-p/163247#M46315</link>
      <description>&lt;P&gt;Those log messages should be from the actual search execution, not the startup... so they're not to blame.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2015 22:50:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-troubleshoot-why-startup-handoff-in-the-Search-Job/m-p/163247#M46315</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2015-06-25T22:50:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why startup.handoff in the Search Job Inspector always seems to take a long time?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-troubleshoot-why-startup-handoff-in-the-Search-Job/m-p/163248#M46316</link>
      <description>&lt;P&gt;Well I am out of ideas, but thanks for your help anyway.&lt;/P&gt;

&lt;P&gt;In the end I was able to improve performance overall by reducing swappiness on the hosts to 10, the search heads seem way more responsive now.&lt;/P&gt;

&lt;P&gt;If someone has any additional ideas on troubleshooting &lt;CODE&gt;startup.handoff&lt;/CODE&gt; it would be great to hear.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2015 20:33:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-troubleshoot-why-startup-handoff-in-the-Search-Job/m-p/163248#M46316</guid>
      <dc:creator>gustavomichels</dc:creator>
      <dc:date>2015-06-26T20:33:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why startup.handoff in the Search Job Inspector always seems to take a long time?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-troubleshoot-why-startup-handoff-in-the-Search-Job/m-p/163249#M46317</link>
      <description>&lt;P&gt;You shouldn't be swapping, ever. Memory is cheap!&lt;/P&gt;</description>
      <pubDate>Sat, 27 Jun 2015 08:38:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-troubleshoot-why-startup-handoff-in-the-Search-Job/m-p/163249#M46317</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2015-06-27T08:38:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why startup.handoff in the Search Job Inspector always seems to take a long time?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-troubleshoot-why-startup-handoff-in-the-Search-Job/m-p/163250#M46318</link>
      <description>&lt;P&gt;I have the same problem too but no memory swap issue. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Execution costs

Duration (seconds)      Component   Invocations Input count Output count
    0.02    command.dedup   16  596 187
    0.01    command.fields  15  2,869   2,869
    0.02    command.prededup    15  2,869   596
    0.02    command.rename  16  187 187
    0.74    command.search  30  2,869   5,738
    0.40    command.search.index    789 -   -
    0.08    command.search.fieldalias   9   2,869   2,869
    0.07    command.search.calcfields   9   2,869   2,869
    0.02    command.search.filter   24  -   -
    0.00    command.search.index.usec_1_8   242 -   -
    0.00    command.search.index.usec_8_64  6   -   -
    0.28    command.search.typer    9   2,869   2,869
    0.12    command.search.lookups  9   2,869   2,869
    0.08    command.search.kv   9   -   -
    0.04    command.search.rawdata  9   -   -
    0.01    command.search.tags 9   2,869   2,869
    0.00    command.search.summary  15  -   -
    0.00    dispatch.check_disk_usage   1   -   -
    1.42    dispatch.createdSearchResultInfrastructure  1   -   -
    0.32    dispatch.evaluate   1   -   -
    0.32    dispatch.evaluate.search    1   -   -
    0.00    dispatch.evaluate.dedup 1   -   -
    0.00    dispatch.evaluate.rename    1   -   -
    2.30    dispatch.fetch  16  -   -
    0.00    dispatch.localSearch    1   -   -
    0.84    dispatch.parserThread   14  -   -
    0.00    dispatch.preview    3   -   -
    0.00    dispatch.readEventsInResults    1   -   -
    0.02    dispatch.results_combiner   16  -   -
    0.00    dispatch.stream.local   1   -   -
    0.73    dispatch.stream.remote  14  -   436,030
    0.31    dispatch.stream.remote.splunkqa2i   4   -   176,291
    0.19    dispatch.stream.remote.splunk4i 4   -   121,692
    0.19    dispatch.stream.remote.splunk2i 4   -   129,755
    0.04    dispatch.stream.remote.splunk1i 2   -   8,292
    0.18    dispatch.timeline   16  -   -
    3.05    dispatch.writeStatus    11  -   -
    0.38    startup.configuration   5   -   -
    8.06    startup.handoff 5   -   -
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 15 Oct 2015 17:28:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-troubleshoot-why-startup-handoff-in-the-Search-Job/m-p/163250#M46318</guid>
      <dc:creator>BP9906</dc:creator>
      <dc:date>2015-10-15T17:28:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why startup.handoff in the Search Job Inspector always seems to take a long time?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-troubleshoot-why-startup-handoff-in-the-Search-Job/m-p/163251#M46319</link>
      <description>&lt;P&gt;Open a new question, and include a pastebinned search.log from that job.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Oct 2015 21:33:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-troubleshoot-why-startup-handoff-in-the-Search-Job/m-p/163251#M46319</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2015-10-15T21:33:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why startup.handoff in the Search Job Inspector always seems to take a long time?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-troubleshoot-why-startup-handoff-in-the-Search-Job/m-p/163252#M46320</link>
      <description>&lt;P&gt;I'm having a similiar issue, with startup.handoff taking the majority of the search time.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;    0.00    command.fields  15  197 197
    0.08    command.search  15  -   197
    0.04    command.search.index    24  -   -
    0.01    command.search.filter   2   -   -
    0.00    command.search.calcfields   2   1,167   1,167
    0.00    command.search.fieldalias   2   1,167   1,167
    0.00    command.search.index.usec_1_8   489 -   -
    0.00    command.search.index.usec_512_4096  5   -   -
    0.02    command.search.rawdata  2   -   -
    0.01    command.search.kv   2   -   -
    0.00    command.search.typer    2   197 197
    0.00    command.search.lookups  2   1,167   1,167
    0.00    command.search.summary  15  -   -
    0.00    command.search.tags 2   197 197
    0.00    dispatch.check_disk_usage   1   -   -
    0.00    dispatch.createdSearchResultInfrastructure  1   -   -
    0.04    dispatch.evaluate   1   -   -
    0.03    dispatch.evaluate.search    1   -   -
    0.04    dispatch.fetch  16  -   -
    0.06    dispatch.localSearch    1   -   -
    0.01    dispatch.readEventsInResults    1   -   -
    0.08    dispatch.stream.local   15  -   -
    0.31    dispatch.timeline   16  -   -
    0.05    dispatch.writeStatus    6   -   -
    0.02    startup.configuration   1   -   -
    0.64    startup.handoff 1   -   -
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 04 Aug 2016 14:38:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-troubleshoot-why-startup-handoff-in-the-Search-Job/m-p/163252#M46320</guid>
      <dc:creator>cegoes</dc:creator>
      <dc:date>2016-08-04T14:38:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why startup.handoff in the Search Job Inspector always seems to take a long time?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-troubleshoot-why-startup-handoff-in-the-Search-Job/m-p/163253#M46321</link>
      <description>&lt;P&gt;From the documentation:  startup.handoff  The time elapsed between the forking of a separate search process and the beginning of useful work of the forked search processes. In other words it is the approximate time it takes to build the search apparatus. This is cumulative across all involved peers. If this takes a long time, it could be indicative of I/O issues with .conf files or the dispatch directory.&lt;/P&gt;

&lt;P&gt;The things that I have seen affecting this have been:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;search head is very busy&lt;/LI&gt;
&lt;LI&gt;indexers are very busy&lt;/LI&gt;
&lt;LI&gt;large search bundles&lt;/LI&gt;
&lt;LI&gt;slow I/O on drive that hosts the splunk ($SPLUNK_HOME)&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;If you are using the SoS app or the Distributed Management Console you should be able to see if your problems are #1 or 2.  &lt;/P&gt;

&lt;P&gt;For 3 - Really large search bundles are most often due to large lookup tables.  You can grab one of the bundles from the search head or indexers, move it to a temp directory and expand it using tar.  Then look and see if one or more directories is very large (du -m --max-depth=1).  This could point you to a lookup table you may not need to distribute.  Sometimes will will see bundle replication timeouts that indicate this problem in the splunkd.log&lt;/P&gt;

&lt;P&gt;4 - more difficult to measure as this could also be due to network utilization when transferring the bundle to the indexers.  But you should be able to measure disk I/O using some tool.&lt;/P&gt;

&lt;P&gt;It could also be that one indexer is much slower than all the others and that will cause the whole startup process to be slow.&lt;/P&gt;

&lt;P&gt;If you find your answer, please post for other's benefit.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2016 15:29:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-troubleshoot-why-startup-handoff-in-the-Search-Job/m-p/163253#M46321</guid>
      <dc:creator>sjohnson_splunk</dc:creator>
      <dc:date>2016-08-04T15:29:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why startup.handoff in the Search Job Inspector always seems to take a long time?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-troubleshoot-why-startup-handoff-in-the-Search-Job/m-p/163254#M46322</link>
      <description>&lt;P&gt;Open a new question, and include a pastebinned search.log from that job.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2016 18:03:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-troubleshoot-why-startup-handoff-in-the-Search-Job/m-p/163254#M46322</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2016-08-04T18:03:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why startup.handoff in the Search Job Inspector always seems to take a long time?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-troubleshoot-why-startup-handoff-in-the-Search-Job/m-p/525395#M148260</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is it possible that splunk changed the way how it calculates the search time? I have searches with "152,98 startup.handoff" and "This search has completed and ... in 2.272 seconds. " so without putting the huge handoff time in there. Looks like benchmark cheating &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Arnim&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 15:25:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-troubleshoot-why-startup-handoff-in-the-Search-Job/m-p/525395#M148260</guid>
      <dc:creator>Administrator</dc:creator>
      <dc:date>2020-10-19T15:25:46Z</dc:date>
    </item>
  </channel>
</rss>

