<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Search Log SearchOperator:kv in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Log-SearchOperator-kv/m-p/317262#M174652</link>
    <description>&lt;P&gt;When I use the Job Inspector to view the Search Log of a completed search, I find hundreds of entries tagged: SearchOperator:kv that seem to have absolutely nothing to do with the sourcetype or datasource of the search ...&lt;/P&gt;

&lt;P&gt;ie: I'll see hundreds of regexes that are from EXTRACT-blah-blah ... that are explicitly for other sourcetypes. I'm concerned that I have a configuration issue. Lately we've had some complaints about search performance and I'm currently wondering why all this unrelated noise in the search log? Is Splunk actually trying to perform search time extractions for data that doesn't match the sourcetype the extraction was intended for?&lt;/P&gt;</description>
    <pubDate>Wed, 24 May 2017 23:09:50 GMT</pubDate>
    <dc:creator>pkeller</dc:creator>
    <dc:date>2017-05-24T23:09:50Z</dc:date>
    <item>
      <title>Splunk Search Log SearchOperator:kv</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Log-SearchOperator-kv/m-p/317262#M174652</link>
      <description>&lt;P&gt;When I use the Job Inspector to view the Search Log of a completed search, I find hundreds of entries tagged: SearchOperator:kv that seem to have absolutely nothing to do with the sourcetype or datasource of the search ...&lt;/P&gt;

&lt;P&gt;ie: I'll see hundreds of regexes that are from EXTRACT-blah-blah ... that are explicitly for other sourcetypes. I'm concerned that I have a configuration issue. Lately we've had some complaints about search performance and I'm currently wondering why all this unrelated noise in the search log? Is Splunk actually trying to perform search time extractions for data that doesn't match the sourcetype the extraction was intended for?&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2017 23:09:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Log-SearchOperator-kv/m-p/317262#M174652</guid>
      <dc:creator>pkeller</dc:creator>
      <dc:date>2017-05-24T23:09:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Search Log SearchOperator:kv</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Log-SearchOperator-kv/m-p/317263#M174653</link>
      <description>&lt;P&gt;I too have this question, was hoping if any resolutions have been found. I am running into the same issue.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2017 21:20:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Log-SearchOperator-kv/m-p/317263#M174653</guid>
      <dc:creator>clanier</dc:creator>
      <dc:date>2017-10-30T21:20:25Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Search Log SearchOperator:kv</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Log-SearchOperator-kv/m-p/317264#M174654</link>
      <description>&lt;P&gt;This is hard to answer without any detailed knowledge of your setup. But I would start by checking for &lt;CODE&gt;global&lt;/CODE&gt; permission of Apps and change it back to be &lt;CODE&gt;App&lt;/CODE&gt;, next would be to check any rouge &lt;CODE&gt;*&lt;/CODE&gt; entries in &lt;CODE&gt;props.conf&lt;/CODE&gt;, last but not least run your searches in &lt;CODE&gt;Fast Mode&lt;/CODE&gt; and add any needed field in the base search.&lt;/P&gt;

&lt;P&gt;Hope this helps, even it might not be the solution&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2017 21:36:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Log-SearchOperator-kv/m-p/317264#M174654</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2017-10-30T21:36:30Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Search Log SearchOperator:kv</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Log-SearchOperator-kv/m-p/317265#M174655</link>
      <description>&lt;P&gt;Thanks MuS I appreciate the answer, I will investigate these areas shortly.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Oct 2017 12:12:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Log-SearchOperator-kv/m-p/317265#M174655</guid>
      <dc:creator>clanier</dc:creator>
      <dc:date>2017-10-31T12:12:38Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Search Log SearchOperator:kv</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Log-SearchOperator-kv/m-p/317266#M174656</link>
      <description>&lt;P&gt;Hey MuS. Seems as if what I am referring to are Calculated-Fields. I have asked this [question][1], I when I do searches on a sourcetype for example syslog, search.log reflects calculated-fields from other sourcetypes. I am looking about how to deactivate these calculated-fields in searching not pertaining to them. Thanks, Cam.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/586903/calculated-fields-automatically-included-in-search.html?minQuestionBodyLength=80"&gt;https://answers.splunk.com/answers/586903/calculated-fields-automatically-included-in-search.html?minQuestionBodyLength=80&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Nov 2017 18:21:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Log-SearchOperator-kv/m-p/317266#M174656</guid>
      <dc:creator>clanier</dc:creator>
      <dc:date>2017-11-01T18:21:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Search Log SearchOperator:kv</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Log-SearchOperator-kv/m-p/317267#M174657</link>
      <description>&lt;P&gt;I dont feel that this question has been answered yet. @MuS suggestions may work, but doesnt help in a large environment when things need to be global.&lt;/P&gt;

&lt;P&gt;The big question here is why is splunk trying to do  sourcetype extracts on a source that has nothing to do with the sourcetype being searched?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2017 17:41:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Search-Log-SearchOperator-kv/m-p/317267#M174657</guid>
      <dc:creator>jtrujillo</dc:creator>
      <dc:date>2017-11-10T17:41:03Z</dc:date>
    </item>
  </channel>
</rss>

