<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Queries are timing out in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Queries-are-timing-out/m-p/25189#M4711</link>
    <description>&lt;P&gt;I'm not sure if your data will allow for this, but this would certainly be faster if it doesn't cause your search to break:&lt;/P&gt;

&lt;P&gt;Option 1:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=app_summary_index report=app_report attr1="&amp;lt;user-selected-value&amp;gt;" | stats count as Count by attr1, attr2, _time | timechart span=1h sum(Count) by attr2
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If that works, then this should be even faster:&lt;/P&gt;

&lt;P&gt;Option 2:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=app_summary_index report=app_report attr1="&amp;lt;user-selected-value&amp;gt;" | timechart span=1h count as Count by attr2
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The purpose of this is simply to reduce the number of events in the main search; reducing the number of events that splunk has to process is the single biggest way to improve search performance.&lt;/P&gt;

&lt;P&gt;If neither of the above, work, then this could be slightly faster.   But it's hard to know for sure, and I doubt it would be enough to get past your issue, but here goes...&lt;/P&gt;

&lt;P&gt;Option 3:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=app_summary_index report=app_report | bucket _time span=1h | stats count as Count by attr1, attr2, _time | search attr1="&amp;lt;user-selected-value&amp;gt;" | timechart span=1h count by attr2  
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;/P&gt;&lt;HR /&gt;&lt;P&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Update:&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Option 4:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=app_summary_index report=app_report | search attr1="&amp;lt;user-selected-value&amp;gt;" | timechart span=1h count as Count by attr2
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Fri, 06 Aug 2010 02:09:10 GMT</pubDate>
    <dc:creator>Lowell</dc:creator>
    <dc:date>2010-08-06T02:09:10Z</dc:date>
    <item>
      <title>Queries are timing out</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Queries-are-timing-out/m-p/25185#M4707</link>
      <description>&lt;P&gt;Hi  &lt;/P&gt;

&lt;P&gt;We have a few charts that display summary-indexed data. The charts take a couple of form inputs including &lt;CODE&gt;_time&lt;/CODE&gt; and an application specific parameter (&lt;CODE&gt;attr1&lt;/CODE&gt;). The charts display data for a time range of a week. But when &lt;CODE&gt;"All Time"&lt;/CODE&gt; or &lt;CODE&gt;"Year to date"&lt;/CODE&gt; is chosen, the queries time out.  &lt;/P&gt;

&lt;P&gt;The query is of the form:  &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=app_summary_index report=app_report | stats count as Count by attr1, attr2, _time  
  | search attr1="&amp;lt;user-selected-value&amp;gt;"  | timechart span=1h sum(Count) by attr2  
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The above query had close to 26K events for the past week.  &lt;/P&gt;

&lt;P&gt;Could you let me know where/how to start researching on what should be optimized? We are using Splunk version 4.0.9.  &lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Aug 2010 21:49:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Queries-are-timing-out/m-p/25185#M4707</guid>
      <dc:creator>sranga</dc:creator>
      <dc:date>2010-08-04T21:49:46Z</dc:date>
    </item>
    <item>
      <title>Re: Queries are timing out</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Queries-are-timing-out/m-p/25186#M4708</link>
      <description>&lt;P&gt;Please add additional information to you question.  Examples include:  how many events you are looking at for a week.  Do you have any search time restrictions setup on your environment?  What kind of data is being represented?  Have you attempted to use the "inspect search" feature in the "Actions" menu.  (You may need to manually run the search.)  ...  Please use the "edit" link below you question to add more details.  The more details you can provide the more likely a helpful answer can be found.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Aug 2010 01:14:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Queries-are-timing-out/m-p/25186#M4708</guid>
      <dc:creator>Lowell</dc:creator>
      <dc:date>2010-08-05T01:14:22Z</dc:date>
    </item>
    <item>
      <title>Re: Queries are timing out</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Queries-are-timing-out/m-p/25187#M4709</link>
      <description>&lt;P&gt;Thanks. I don't know what "search time restrictions" mean. I don't see a "inspect search" feature in the "Actions" menu. We are using version 4.0.9.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Aug 2010 05:38:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Queries-are-timing-out/m-p/25187#M4709</guid>
      <dc:creator>sranga</dc:creator>
      <dc:date>2010-08-05T05:38:14Z</dc:date>
    </item>
    <item>
      <title>Re: Queries are timing out</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Queries-are-timing-out/m-p/25188#M4710</link>
      <description>&lt;P&gt;Inspect search was added around 4.1.1, if I remember correctly.  It's very helpful in tracking down issues.  By search restrictions, I'm talking about stuff in &lt;CODE&gt;limits.conf&lt;/CODE&gt; or role-based search limitations; If you don't know what I'm taking about, then you probably haven't changed them; but you could easily test by running a search as an admin user vs a regular user and see if it makes a difference.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Aug 2010 02:02:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Queries-are-timing-out/m-p/25188#M4710</guid>
      <dc:creator>Lowell</dc:creator>
      <dc:date>2010-08-06T02:02:34Z</dc:date>
    </item>
    <item>
      <title>Re: Queries are timing out</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Queries-are-timing-out/m-p/25189#M4711</link>
      <description>&lt;P&gt;I'm not sure if your data will allow for this, but this would certainly be faster if it doesn't cause your search to break:&lt;/P&gt;

&lt;P&gt;Option 1:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=app_summary_index report=app_report attr1="&amp;lt;user-selected-value&amp;gt;" | stats count as Count by attr1, attr2, _time | timechart span=1h sum(Count) by attr2
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If that works, then this should be even faster:&lt;/P&gt;

&lt;P&gt;Option 2:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=app_summary_index report=app_report attr1="&amp;lt;user-selected-value&amp;gt;" | timechart span=1h count as Count by attr2
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The purpose of this is simply to reduce the number of events in the main search; reducing the number of events that splunk has to process is the single biggest way to improve search performance.&lt;/P&gt;

&lt;P&gt;If neither of the above, work, then this could be slightly faster.   But it's hard to know for sure, and I doubt it would be enough to get past your issue, but here goes...&lt;/P&gt;

&lt;P&gt;Option 3:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=app_summary_index report=app_report | bucket _time span=1h | stats count as Count by attr1, attr2, _time | search attr1="&amp;lt;user-selected-value&amp;gt;" | timechart span=1h count by attr2  
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;/P&gt;&lt;HR /&gt;&lt;P&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Update:&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Option 4:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=app_summary_index report=app_report | search attr1="&amp;lt;user-selected-value&amp;gt;" | timechart span=1h count as Count by attr2
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 06 Aug 2010 02:09:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Queries-are-timing-out/m-p/25189#M4711</guid>
      <dc:creator>Lowell</dc:creator>
      <dc:date>2010-08-06T02:09:10Z</dc:date>
    </item>
    <item>
      <title>Re: Queries are timing out</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Queries-are-timing-out/m-p/25190#M4712</link>
      <description>&lt;P&gt;Thanks Lowell. The first two options wouldn't work for us since we have to filter based on a user-input value for "attr1". The third option is what we have already. The summary indexed events are bucketed over the hour.&lt;/P&gt;</description>
      <pubDate>Sat, 07 Aug 2010 00:45:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Queries-are-timing-out/m-p/25190#M4712</guid>
      <dc:creator>sranga</dc:creator>
      <dc:date>2010-08-07T00:45:50Z</dc:date>
    </item>
    <item>
      <title>Re: Queries are timing out</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Queries-are-timing-out/m-p/25191#M4713</link>
      <description>&lt;P&gt;I'm confused on why you are ruling options 1 and 2.  It's perfectly acceptable for a form search to take a form variable and use it as part of the base search; in fact it is much faster.  Unless there is some complexity that you haven't posted?   As long as the "attr1" field exists in the events you are searching on, then you should be able to simply use:  &lt;CODE&gt;index=app_summary_index report=app_report attr1="$token$" | ...&lt;/CODE&gt; in your &lt;CODE&gt;searchTemplate&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Sat, 07 Aug 2010 01:40:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Queries-are-timing-out/m-p/25191#M4713</guid>
      <dc:creator>Lowell</dc:creator>
      <dc:date>2010-08-07T01:40:14Z</dc:date>
    </item>
    <item>
      <title>Re: Queries are timing out</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Queries-are-timing-out/m-p/25192#M4714</link>
      <description>&lt;P&gt;So, why do you have both a &lt;CODE&gt;stats&lt;/CODE&gt; and then &lt;CODE&gt;timechart&lt;/CODE&gt;, is there some reason why you can't combine these like I've done in Option 2 and 4.&lt;/P&gt;</description>
      <pubDate>Sat, 07 Aug 2010 06:40:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Queries-are-timing-out/m-p/25192#M4714</guid>
      <dc:creator>Lowell</dc:creator>
      <dc:date>2010-08-07T06:40:42Z</dc:date>
    </item>
  </channel>
</rss>

