<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Slow search when using field &amp;quot;host&amp;quot; in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Slow-search-when-using-field-quot-host-quot/m-p/572004#M199330</link>
    <description>&lt;P&gt;That's very unusual. The only explanation that comes to mind is that it's not connected in any way to the search itself, it's just that you've hit the search number limit and had to wait for "free" search peers. And only accidentaly it correlated to a change in your search. But if it's repeatable (every time adding the host field to the search results in this long search and without it the search runs quickly), that explanation would have to be wrong.&lt;/P&gt;</description>
    <pubDate>Fri, 22 Oct 2021 12:25:41 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2021-10-22T12:25:41Z</dc:date>
    <item>
      <title>Slow search when using field "host"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Slow-search-when-using-field-quot-host-quot/m-p/571985#M199319</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;I have strange Splunk behavior regarding one of the indexes but first a little bit of background:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Environment is indexer cluster with 1 SH&lt;/LI&gt;&lt;LI&gt;Proxy logs are getting ingested from syslog server via universal forwarder (monitor input)&lt;/LI&gt;&lt;LI&gt;Monitor input uses host_segment option to extract host data&lt;/LI&gt;&lt;LI&gt;Sourcetype is set to "cisco:wsa:squid" from splunkbase app "Splunk_TA_cisco-wsa".&lt;/LI&gt;&lt;LI&gt;I'm not using any local configuration for that sourcetype (on any instance)&lt;/LI&gt;&lt;LI&gt;There are no props.conf stanzas that apply configuration based on source or host (i.e. [host::something]) for this specific source or host&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;The issue:&lt;/P&gt;&lt;P&gt;When I'm using the search 1 (with field "host") in fast mode it is 10 to 20 times slower than using search 2.&lt;/P&gt;&lt;P&gt;Search 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=my_index sourcetype=cisco:wsa:squid| fields _time, _indextime, source, sourcetype, host, index, splunk_server, _raw&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Search 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=my_index sourcetype=cisco:wsa:squid| fields _time, _indextime, source, sourcetype, index, splunk_server, _raw&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have already reviewed full configuration an there is no configuration on any of the instances that is modifying field "host" in any way and when I use it in my search it is drastically slower which is causing issues further down the line.&lt;/P&gt;&lt;P&gt;This issue does not manifest on other indexes. All indexes are configured with same options in indexes.conf&lt;/P&gt;&lt;P&gt;Hope someone can give me a good clue for troubleshooting.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2021 11:30:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Slow-search-when-using-field-quot-host-quot/m-p/571985#M199319</guid>
      <dc:creator>dalbreht</dc:creator>
      <dc:date>2021-10-22T11:30:39Z</dc:date>
    </item>
    <item>
      <title>Re: Slow search when using field "host"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Slow-search-when-using-field-quot-host-quot/m-p/571989#M199322</link>
      <description>&lt;P&gt;Inspect both jobs and see what the difference is because it's counterintuitive. Especially that host is an indexed field.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2021 11:40:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Slow-search-when-using-field-quot-host-quot/m-p/571989#M199322</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-10-22T11:40:02Z</dc:date>
    </item>
    <item>
      <title>Re: Slow search when using field "host"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Slow-search-when-using-field-quot-host-quot/m-p/571991#M199324</link>
      <description>&lt;P&gt;Haven't seen any events in search.log that would explain this behavior. No errors or warnings.&lt;/P&gt;&lt;P&gt;Execution time analysis shows only longer times in "dispatch.stream.remote" section (fetching data from indexers).&lt;/P&gt;&lt;P&gt;Data is equally balanced across cluster so it is not the issue of single node.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2021 11:55:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Slow-search-when-using-field-quot-host-quot/m-p/571991#M199324</guid>
      <dc:creator>dalbreht</dc:creator>
      <dc:date>2021-10-22T11:55:22Z</dc:date>
    </item>
    <item>
      <title>Re: Slow search when using field "host"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Slow-search-when-using-field-quot-host-quot/m-p/572002#M199329</link>
      <description>&lt;P&gt;Adding side-by-side view of search performance&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dalbreht_0-1634905179890.png" style="width: 765px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16552i78A0A59D3825B944/image-dimensions/765x232?v=v2" width="765" height="232" role="button" title="dalbreht_0-1634905179890.png" alt="dalbreht_0-1634905179890.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2021 12:19:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Slow-search-when-using-field-quot-host-quot/m-p/572002#M199329</guid>
      <dc:creator>dalbreht</dc:creator>
      <dc:date>2021-10-22T12:19:51Z</dc:date>
    </item>
    <item>
      <title>Re: Slow search when using field "host"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Slow-search-when-using-field-quot-host-quot/m-p/572004#M199330</link>
      <description>&lt;P&gt;That's very unusual. The only explanation that comes to mind is that it's not connected in any way to the search itself, it's just that you've hit the search number limit and had to wait for "free" search peers. And only accidentaly it correlated to a change in your search. But if it's repeatable (every time adding the host field to the search results in this long search and without it the search runs quickly), that explanation would have to be wrong.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2021 12:25:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Slow-search-when-using-field-quot-host-quot/m-p/572004#M199330</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-10-22T12:25:41Z</dc:date>
    </item>
    <item>
      <title>Re: Slow search when using field "host"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Slow-search-when-using-field-quot-host-quot/m-p/572005#M199331</link>
      <description>&lt;P&gt;It is repeatable&amp;nbsp; and only manifests on this index when I use field "host". In all other cases searches run normally and "fast".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2021 12:29:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Slow-search-when-using-field-quot-host-quot/m-p/572005#M199331</guid>
      <dc:creator>dalbreht</dc:creator>
      <dc:date>2021-10-22T12:29:19Z</dc:date>
    </item>
  </channel>
</rss>

