<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SPlunk Searches slow in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/SPlunk-Searches-slow/m-p/318374#M160997</link>
    <description>&lt;P&gt;again, there are plenty of points to check here, did you look at ulimits and THP?&lt;BR /&gt;
was splunk working fine in the past? did you change anything lately? if it was always slow, what are the specs for Indexers and SH, CPU (cores) and Memory?&lt;BR /&gt;
how many forwarders you have sending data? how much data do you index every day on each inxeder? &lt;/P&gt;</description>
    <pubDate>Thu, 25 May 2017 14:37:55 GMT</pubDate>
    <dc:creator>adonio</dc:creator>
    <dc:date>2017-05-25T14:37:55Z</dc:date>
    <item>
      <title>SPlunk Searches slow</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SPlunk-Searches-slow/m-p/318365#M160988</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I am facing challenges to search query in SPlunk 6.4.1 environment But Splunk Performance is very slow.&lt;BR /&gt;
We have 1 search head and 2 Indexers, 1 Deployment sevrers and 1 liscence master server.&lt;/P&gt;

&lt;P&gt;Please help how we can improve the performance and search query faster.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Sahil&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2017 12:53:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SPlunk-Searches-slow/m-p/318365#M160988</guid>
      <dc:creator>sahils</dc:creator>
      <dc:date>2017-05-25T12:53:19Z</dc:date>
    </item>
    <item>
      <title>Re: SPlunk Searches slow</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SPlunk-Searches-slow/m-p/318366#M160989</link>
      <description>&lt;P&gt;can you give any detail about how much data your are searching through? are there ways we can help make the searches more efficient, such as syntax or changing a time window? is it one or a few searches or all searches?&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2017 13:01:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SPlunk-Searches-slow/m-p/318366#M160989</guid>
      <dc:creator>cmerriman</dc:creator>
      <dc:date>2017-05-25T13:01:30Z</dc:date>
    </item>
    <item>
      <title>Re: SPlunk Searches slow</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SPlunk-Searches-slow/m-p/318367#M160990</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;It is for all searches and data is in MB's, I change the time period also But it is very slow.&lt;/P&gt;

&lt;P&gt;Can you please suggest&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Sahil &lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2017 13:04:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SPlunk-Searches-slow/m-p/318367#M160990</guid>
      <dc:creator>sahils</dc:creator>
      <dc:date>2017-05-25T13:04:20Z</dc:date>
    </item>
    <item>
      <title>Re: SPlunk Searches slow</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SPlunk-Searches-slow/m-p/318368#M160991</link>
      <description>&lt;P&gt;is it linux or windows?&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2017 13:04:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SPlunk-Searches-slow/m-p/318368#M160991</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2017-05-25T13:04:21Z</dc:date>
    </item>
    <item>
      <title>Re: SPlunk Searches slow</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SPlunk-Searches-slow/m-p/318369#M160992</link>
      <description>&lt;P&gt;It is Linux Servers.&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2017 13:06:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SPlunk-Searches-slow/m-p/318369#M160992</guid>
      <dc:creator>sahils</dc:creator>
      <dc:date>2017-05-25T13:06:43Z</dc:date>
    </item>
    <item>
      <title>Re: SPlunk Searches slow</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SPlunk-Searches-slow/m-p/318370#M160993</link>
      <description>&lt;P&gt;there are plenty of things to check here, machines specs, THP ulimit, also check internally, how is your cpu usage looks like? &lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2017 13:41:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SPlunk-Searches-slow/m-p/318370#M160993</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2017-05-25T13:41:24Z</dc:date>
    </item>
    <item>
      <title>Re: SPlunk Searches slow</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SPlunk-Searches-slow/m-p/318371#M160994</link>
      <description>&lt;P&gt;I have SPlunk on SPlunk app which  i am checking CPU usage and disk space is fine &lt;/P&gt;

&lt;P&gt;MemTotal:       32871212 kB&lt;BR /&gt;
MemFree:         9258220 kB&lt;BR /&gt;
Buffers:         1049452 kB&lt;BR /&gt;
Cached:         13493864 kB&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2017 14:08:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SPlunk-Searches-slow/m-p/318371#M160994</guid>
      <dc:creator>sahils</dc:creator>
      <dc:date>2017-05-25T14:08:48Z</dc:date>
    </item>
    <item>
      <title>Re: SPlunk Searches slow</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SPlunk-Searches-slow/m-p/318372#M160995</link>
      <description>&lt;P&gt;can you try and be more specific? what exactly is slow? how long a basic search takes?&lt;BR /&gt;
try: &lt;CODE&gt;index = _internal | stats count by sourcetype&lt;/CODE&gt; &lt;BR /&gt;
do it in fast mode in the last 60 minutes&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2017 14:25:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SPlunk-Searches-slow/m-p/318372#M160995</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2017-05-25T14:25:06Z</dc:date>
    </item>
    <item>
      <title>Re: SPlunk Searches slow</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SPlunk-Searches-slow/m-p/318373#M160996</link>
      <description>&lt;P&gt;I takes almost more than  minute for search result which is more than normal search&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;count
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;aws:cloudtrail:log  1007&lt;BR /&gt;
aws:cloudwatch:log  26088&lt;BR /&gt;
aws:cloudwatchlogs:log  79024&lt;BR /&gt;
aws:config:log  734&lt;BR /&gt;
aws:description:log 1955&lt;BR /&gt;
aws:s3:log  6124&lt;BR /&gt;
mongod  129&lt;BR /&gt;
nfs0000000009669cb  162&lt;BR /&gt;
scheduler   174&lt;BR /&gt;
splunk-powershell.ps-2  1932&lt;BR /&gt;
splunk-powershell.ps-too_small  722&lt;BR /&gt;
splunk_ta_aws_proxy_conf-2  182&lt;BR /&gt;
splunk_user_realnames   86&lt;BR /&gt;
splunkd 6838386&lt;BR /&gt;
splunkd_access  124312&lt;BR /&gt;
splunkd_conf    2&lt;BR /&gt;
splunkd_remote_searches 424&lt;BR /&gt;
splunkd_stderr  5&lt;BR /&gt;
ta_box-3    1&lt;BR /&gt;
ta_box-4    490&lt;BR /&gt;
ta_frmk-5   288&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Sahil&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 14:15:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SPlunk-Searches-slow/m-p/318373#M160996</guid>
      <dc:creator>sahils</dc:creator>
      <dc:date>2020-09-29T14:15:12Z</dc:date>
    </item>
    <item>
      <title>Re: SPlunk Searches slow</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SPlunk-Searches-slow/m-p/318374#M160997</link>
      <description>&lt;P&gt;again, there are plenty of points to check here, did you look at ulimits and THP?&lt;BR /&gt;
was splunk working fine in the past? did you change anything lately? if it was always slow, what are the specs for Indexers and SH, CPU (cores) and Memory?&lt;BR /&gt;
how many forwarders you have sending data? how much data do you index every day on each inxeder? &lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2017 14:37:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SPlunk-Searches-slow/m-p/318374#M160997</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2017-05-25T14:37:55Z</dc:date>
    </item>
    <item>
      <title>Re: SPlunk Searches slow</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SPlunk-Searches-slow/m-p/318375#M160998</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;
Do you have the same behavior with all sourcetypes? &lt;BR /&gt;
I had a similar case before with Bluecoat default app, and after a lot troubleshooting I found that the regex used for filed extractions at search time was the reason.&lt;/P&gt;

&lt;P&gt;After I used delimiter based field extractions (it was space in case of Bluecoat logs) the slow performance in searches disappeared.  &lt;/P&gt;

&lt;P&gt;Hope this helps.&lt;/P&gt;

&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2017 14:38:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SPlunk-Searches-slow/m-p/318375#M160998</guid>
      <dc:creator>aakwah</dc:creator>
      <dc:date>2017-05-25T14:38:21Z</dc:date>
    </item>
    <item>
      <title>Re: SPlunk Searches slow</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SPlunk-Searches-slow/m-p/318376#M160999</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;It  is for all Search query  and source type , Please let me know How I can removed regex exp for all fields.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Sahil&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2017 15:37:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SPlunk-Searches-slow/m-p/318376#M160999</guid>
      <dc:creator>sahils</dc:creator>
      <dc:date>2017-05-25T15:37:04Z</dc:date>
    </item>
    <item>
      <title>Re: SPlunk Searches slow</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SPlunk-Searches-slow/m-p/318377#M161000</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;This happened 3 days back, We didn't change anything, We have 3 forwarders sending data.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Sahil&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2017 15:38:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SPlunk-Searches-slow/m-p/318377#M161000</guid>
      <dc:creator>sahils</dc:creator>
      <dc:date>2017-05-25T15:38:29Z</dc:date>
    </item>
    <item>
      <title>Re: SPlunk Searches slow</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SPlunk-Searches-slow/m-p/318378#M161001</link>
      <description>&lt;P&gt;Filed extraction configurations do exist on props.conf and transforms conf on the search head, you will find all Regex's there if any, each sourcetype sould have its own stanza on props.conf .&lt;/P&gt;

&lt;P&gt;But as long this issue is affecting all sourcetypes then it is a global issue and not related to certain sourcetype field extraction.&lt;/P&gt;

&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2017 16:00:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SPlunk-Searches-slow/m-p/318378#M161001</guid>
      <dc:creator>aakwah</dc:creator>
      <dc:date>2017-05-25T16:00:34Z</dc:date>
    </item>
    <item>
      <title>Re: SPlunk Searches slow</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SPlunk-Searches-slow/m-p/318379#M161002</link>
      <description>&lt;P&gt;try and concentrate on what happened 3 days ago...&lt;BR /&gt;
try also to search for warning and errors in _internal index&lt;/P&gt;</description>
      <pubDate>Sat, 27 May 2017 00:57:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SPlunk-Searches-slow/m-p/318379#M161002</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2017-05-27T00:57:27Z</dc:date>
    </item>
    <item>
      <title>Re: SPlunk Searches slow</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SPlunk-Searches-slow/m-p/318380#M161003</link>
      <description>&lt;P&gt;There has been some great comments and work by aakwah, adonio and cmerriman.  Allow me to recap for the audience, then just take a stab at a solution (or at least problem identification).&lt;/P&gt;

&lt;P&gt;Your searches are slow.  &lt;CODE&gt;index = _internal earliest=-60m | stats count by sourcetype&lt;/CODE&gt; takes a minute or more to return when performed over a one hour period.  This is over about 250,000 events.&lt;/P&gt;

&lt;P&gt;For reference, my setup at work is similar in topology (I have several SHs, but otherwise only a pair of clustered indexers) and seems fast enough to me.  It does that same search in the following amount of time when I run it in verbose mode:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;This search has completed and has returned 33 results by scanning 734,337 events in 41.769 seconds
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;When I run it in fast mode (upper right corner of the search window just under the time selector), It reports&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;This search has completed and has returned 33 results by scanning 734,720 events in 3.227 seconds 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Which is more than an order of magnitude faster.  &lt;/P&gt;

&lt;P&gt;That's &lt;STRONG&gt;one simple optimization&lt;/STRONG&gt; - if you are running all searches in verbose mode, maybe switching to fast or smart mode.  (Smart mode is somewhere between the two - often it's nearly as fast as fast mode).&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Secondly&lt;/STRONG&gt;, I'd GUESS that you are still hitting a system bottleneck.  You haven't provided enough information to know which bottleneck, but usually it's one of two things: IOPS on the indexer or CPU on the various machines.  &lt;/P&gt;

&lt;P&gt;IOPS is usually the culprit.  What disks do you have under your indexers?  If it's marginal (under 800 or 1000 IOPS) then there's likely the rest of your problem.  In order for spinning disks to provide 1000 IOPS, you'd be looking at more than 8x 15,000 rpm disks in Raid 10, and probably 20 or more 7200 RPM disks in R10.  If you have fewer than that per server, or if anything's in R5 or god forbid R6, it's highly likely that's the issue.  If you have SSDs, well, you shouldn't have any serious IOPS issues.  But "shouldn't have" doesn't mean "don't have" and I'd check stuff anyway.&lt;/P&gt;

&lt;P&gt;Otherwise, spend some time watching the 'top' utility on the indexers while you run searches.  Watch the CPU and disk times.  The utility &lt;CODE&gt;iostat&lt;/CODE&gt; from the sysstat install can also be very helpful.&lt;/P&gt;

&lt;P&gt;If you find you have an issue and would like help fixing it (or confirming what you should do about anything you've found), please help us by compiling the information you've found together into a nice summary and pasting it in.  If all you explain is "I ran iostat it says my disks are slow", then we'll probably only be able to say "buy faster disks".  If you instead tell us you have six 7200 RPM 4 TB disks in R5 on an HP 840 controller with 2 GB of RAM, then we can give you specific advice.  The answer still may be "buy more/faster disks" but at least then we can suggest "intermediate" solutions that may help signficantly without being too expensive.&lt;/P&gt;</description>
      <pubDate>Sat, 27 May 2017 03:11:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SPlunk-Searches-slow/m-p/318380#M161003</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2017-05-27T03:11:33Z</dc:date>
    </item>
  </channel>
</rss>

