<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Configuration initialization took longer than expected when dispatching a search in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Configuration-initialization-took-longer-than-expected-when/m-p/755478#M242938</link>
    <description>&lt;P&gt;Hello Gregski11. The timeout setting simple tells splunk to warn you about it, not to disallow the search.&amp;nbsp;the default is 3000ms, so check that your local limits is even readable by splunk. There could be several reasons for the search taking so long to dispatch, such as permission on the directory where the artifacts are created, or even on you limits.conf in your local (if splunk cant read it, it will use the default version).&amp;nbsp; if the disk where the artifacts are create is very slow for some reason, then it could just be taking a while to create.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 13 Nov 2025 14:08:37 GMT</pubDate>
    <dc:creator>nyc_jason</dc:creator>
    <dc:date>2025-11-13T14:08:37Z</dc:date>
    <item>
      <title>Configuration initialization took longer than expected when dispatching a search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Configuration-initialization-took-longer-than-expected-when/m-p/755432#M242935</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I must admit what is happening makes no sense. Take this error for example:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;[OurIndexer01,OurIndexer02,OurIndexer03] Configuration initialization for C:\Program Files\Splunk\var\run\searchpeers\OurSearchHead01-1762950946 took longer than expected (10735ms) when dispatching a search with search ID remote_OurSearchHead01_1762951365.773. This might indicate an issue with underlying storage performance or the knowledge bundle size. If you want this message displayed more or less often, change the value of the 'search_startup_config_timeout_ms' setting in "limits.conf" to a lower or higher number.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;that error says, this search took about 10 seconds and that's too long according to Splunk, well how can that be if in our limits.conf file on this Search Head we have the following stanza?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;[search]&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;search_startup_config_timeout_ms = 30000&lt;BR /&gt;&lt;BR /&gt;FYI we are on the latest version of Splunk 10.x&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Nov 2025 12:57:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Configuration-initialization-took-longer-than-expected-when/m-p/755432#M242935</guid>
      <dc:creator>Gregski11</dc:creator>
      <dc:date>2025-11-12T12:57:25Z</dc:date>
    </item>
    <item>
      <title>Re: Configuration initialization took longer than expected when dispatching a search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Configuration-initialization-took-longer-than-expected-when/m-p/755478#M242938</link>
      <description>&lt;P&gt;Hello Gregski11. The timeout setting simple tells splunk to warn you about it, not to disallow the search.&amp;nbsp;the default is 3000ms, so check that your local limits is even readable by splunk. There could be several reasons for the search taking so long to dispatch, such as permission on the directory where the artifacts are created, or even on you limits.conf in your local (if splunk cant read it, it will use the default version).&amp;nbsp; if the disk where the artifacts are create is very slow for some reason, then it could just be taking a while to create.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Nov 2025 14:08:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Configuration-initialization-took-longer-than-expected-when/m-p/755478#M242938</guid>
      <dc:creator>nyc_jason</dc:creator>
      <dc:date>2025-11-13T14:08:37Z</dc:date>
    </item>
    <item>
      <title>Re: Configuration initialization took longer than expected when dispatching a search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Configuration-initialization-took-longer-than-expected-when/m-p/755482#M242939</link>
      <description>&lt;P&gt;Another notorious cause for huge knowledge bundle is when someone does a big search and happily ends it with | outputlookup. I've seen several gigabytes of data dragged pointlessly back and forth because of that.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Nov 2025 15:36:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Configuration-initialization-took-longer-than-expected-when/m-p/755482#M242939</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-11-13T15:36:46Z</dc:date>
    </item>
  </channel>
</rss>

