<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Search query taking ages to finish in Splunk 7.0.1 in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Search-query-taking-ages-to-finish-in-Splunk-7-0-1/m-p/309384#M92799</link>
    <description>&lt;P&gt;Same behavior I see on my setup.  My query was running fine on 6.5.2 (within 2 mins) and now it is taking more time (90 mins) on 7.0.2. Is there any change happened on 7.0.x? I don't see any error msg on splunkd log too. There is no clue. &lt;/P&gt;</description>
    <pubDate>Mon, 05 Mar 2018 06:19:08 GMT</pubDate>
    <dc:creator>sarfarajsayyad</dc:creator>
    <dc:date>2018-03-05T06:19:08Z</dc:date>
    <item>
      <title>Search query taking ages to finish in Splunk 7.0.1</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-query-taking-ages-to-finish-in-Splunk-7-0-1/m-p/309380#M92795</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I have upgraded Splunk Enterprise to 7.0.1. One of the search query is taking ages to finish it. Same query finished quickly in Splunk 6.x.&lt;/P&gt;

&lt;P&gt;Splunk 6.6.1 = 5 secs&lt;BR /&gt;
Splunk 7.0.1 = 26 mins (still running) &lt;/P&gt;

&lt;P&gt;Does anyone have encounter such situation  or  have idea for this behaviour in Splunk 7. &lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/4159i6B89D54EC069EA2D/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2018 13:29:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-query-taking-ages-to-finish-in-Splunk-7-0-1/m-p/309380#M92795</guid>
      <dc:creator>AKG1_old1</dc:creator>
      <dc:date>2018-01-17T13:29:29Z</dc:date>
    </item>
    <item>
      <title>Re: Search query taking ages to finish in Splunk 7.0.1</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-query-taking-ages-to-finish-in-Splunk-7-0-1/m-p/309381#M92796</link>
      <description>&lt;P&gt;In the first search its written before 17/1/2018 from how long do you have data in your system?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2018 13:45:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-query-taking-ages-to-finish-in-Splunk-7-0-1/m-p/309381#M92796</guid>
      <dc:creator>mayurr98</dc:creator>
      <dc:date>2018-01-17T13:45:47Z</dc:date>
    </item>
    <item>
      <title>Re: Search query taking ages to finish in Splunk 7.0.1</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-query-taking-ages-to-finish-in-Splunk-7-0-1/m-p/309382#M92797</link>
      <description>&lt;P&gt;file is created on 17/01/2018 06:27:12. So its having data for few hours. &lt;/P&gt;

&lt;P&gt;same file is taking by both Splunk version.  I am having feeling that as time is specified as "All Time" , Splunk 7 is not specifically looking for specified file. It's trying to find out data from the begnning of Splunk Time (1st Jan 1970).&lt;/P&gt;

&lt;P&gt;Search is still running.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2018 13:58:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-query-taking-ages-to-finish-in-Splunk-7-0-1/m-p/309382#M92797</guid>
      <dc:creator>AKG1_old1</dc:creator>
      <dc:date>2018-01-17T13:58:47Z</dc:date>
    </item>
    <item>
      <title>Re: Search query taking ages to finish in Splunk 7.0.1</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-query-taking-ages-to-finish-in-Splunk-7-0-1/m-p/309383#M92798</link>
      <description>&lt;P&gt;That's correct. There are a small handful of fields that are extracted at index-time, and unless you've done some intentional work to change that on your system, then the field &lt;CODE&gt;service_name&lt;/CODE&gt; will not be one of them. So now Splunk is searching back through all indexed data looking for any possible matches. Your best bets to make this search run more efficiently are to narrow the time window and specify the index(es) in which you'd like to search. Here's a good guide to provide more of an overview:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/SplunkCloud/6.6.3/Search/Writebettersearches#Tips_for_tuning_your_searches"&gt;http://docs.splunk.com/Documentation/SplunkCloud/6.6.3/Search/Writebettersearches#Tips_for_tuning_your_searches&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2018 14:20:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-query-taking-ages-to-finish-in-Splunk-7-0-1/m-p/309383#M92798</guid>
      <dc:creator>elliotproebstel</dc:creator>
      <dc:date>2018-01-17T14:20:34Z</dc:date>
    </item>
    <item>
      <title>Re: Search query taking ages to finish in Splunk 7.0.1</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-query-taking-ages-to-finish-in-Splunk-7-0-1/m-p/309384#M92799</link>
      <description>&lt;P&gt;Same behavior I see on my setup.  My query was running fine on 6.5.2 (within 2 mins) and now it is taking more time (90 mins) on 7.0.2. Is there any change happened on 7.0.x? I don't see any error msg on splunkd log too. There is no clue. &lt;/P&gt;</description>
      <pubDate>Mon, 05 Mar 2018 06:19:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-query-taking-ages-to-finish-in-Splunk-7-0-1/m-p/309384#M92799</guid>
      <dc:creator>sarfarajsayyad</dc:creator>
      <dc:date>2018-03-05T06:19:08Z</dc:date>
    </item>
    <item>
      <title>Re: Search query taking ages to finish in Splunk 7.0.1</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-query-taking-ages-to-finish-in-Splunk-7-0-1/m-p/309385#M92800</link>
      <description>&lt;P&gt;@agoyal, you second search should be part of your base search&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;yourBaseSearch&amp;gt; "*concurrent mode failure*"
| stats count as FAIL
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Have you tried it this way?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Mar 2018 07:00:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-query-taking-ages-to-finish-in-Splunk-7-0-1/m-p/309385#M92800</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2018-03-05T07:00:45Z</dc:date>
    </item>
    <item>
      <title>Re: Search query taking ages to finish in Splunk 7.0.1</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-query-taking-ages-to-finish-in-Splunk-7-0-1/m-p/309386#M92801</link>
      <description>&lt;P&gt;@sarfarajsayyad , would it be possible for you to share the query?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Mar 2018 07:01:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-query-taking-ages-to-finish-in-Splunk-7-0-1/m-p/309386#M92801</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2018-03-05T07:01:19Z</dc:date>
    </item>
    <item>
      <title>Re: Search query taking ages to finish in Splunk 7.0.1</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-query-taking-ages-to-finish-in-Splunk-7-0-1/m-p/309387#M92802</link>
      <description>&lt;P&gt;That query is having some customer specific info. Cant share here.&lt;BR /&gt;
My point is, the same query is running fine on 6.5.2 and not on 7.0.2. Believe me, I have installed 7.0.2 Splunk enterprise on a new machine without data. Still, it's taking more time. Looks like its nothing related to data. Something is changed in 7.0.x. &lt;/P&gt;

&lt;P&gt;JFYI - In my query, I have 20+  joined on various indexes/lookup.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Mar 2018 08:35:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-query-taking-ages-to-finish-in-Splunk-7-0-1/m-p/309387#M92802</guid>
      <dc:creator>sarfarajsayyad</dc:creator>
      <dc:date>2018-03-05T08:35:51Z</dc:date>
    </item>
    <item>
      <title>Re: Search query taking ages to finish in Splunk 7.0.1</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-query-taking-ages-to-finish-in-Splunk-7-0-1/m-p/309388#M92803</link>
      <description>&lt;P&gt;I see lot of below messages&lt;/P&gt;

&lt;P&gt;02-22-2018 04:06:41.512 INFO  SearchPipeline - Command='eval' doesnt have raw field &lt;BR /&gt;
02-22-2018 04:06:41.512 INFO  SearchPipeline - Command='inputlookup' doesnt have raw field &lt;BR /&gt;
02-22-2018 04:06:41.512 INFO  SearchPipeline - Command='inputlookup' doesnt have raw field &lt;BR /&gt;
02-22-2018 04:06:41.512 INFO  SearchPipeline - Command='eval' doesnt have raw field &lt;BR /&gt;
02-22-2018 04:06:41.512 INFO  SearchPipeline - Command='search' doesnt have raw field &lt;BR /&gt;
02-22-2018 04:06:41.512 INFO  SortOperator - maxmem = 209715200&lt;/P&gt;</description>
      <pubDate>Mon, 05 Mar 2018 09:31:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-query-taking-ages-to-finish-in-Splunk-7-0-1/m-p/309388#M92803</guid>
      <dc:creator>sarfarajsayyad</dc:creator>
      <dc:date>2018-03-05T09:31:54Z</dc:date>
    </item>
    <item>
      <title>Re: Search query taking ages to finish in Splunk 7.0.1</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-query-taking-ages-to-finish-in-Splunk-7-0-1/m-p/309389#M92804</link>
      <description>&lt;P&gt;If I use "|noop search_optimization=false" at the end of my query its giving me result very fast. After cross-checking I got the same result. &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Is there any impact of "|noop search_optimization=false" ?&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Mar 2018 10:20:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-query-taking-ages-to-finish-in-Splunk-7-0-1/m-p/309389#M92804</guid>
      <dc:creator>sarfarajsayyad</dc:creator>
      <dc:date>2018-03-05T10:20:24Z</dc:date>
    </item>
    <item>
      <title>Re: Search query taking ages to finish in Splunk 7.0.1</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-query-taking-ages-to-finish-in-Splunk-7-0-1/m-p/309390#M92805</link>
      <description>&lt;P&gt;@sarfarajsayyad if you have valid Splunk Entitlement, reach out to Splunk Support.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Mar 2018 10:28:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-query-taking-ages-to-finish-in-Splunk-7-0-1/m-p/309390#M92805</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2018-03-05T10:28:20Z</dc:date>
    </item>
    <item>
      <title>Re: Search query taking ages to finish in Splunk 7.0.1</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-query-taking-ages-to-finish-in-Splunk-7-0-1/m-p/309391#M92806</link>
      <description>&lt;P&gt;@sarfarajsayyad @agoyal I am also getting same issue. Were you able to resolve the issue? If yes, what is the solution? Is this issue is specific to new version 7.1.0? &lt;/P&gt;</description>
      <pubDate>Fri, 11 May 2018 09:42:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-query-taking-ages-to-finish-in-Splunk-7-0-1/m-p/309391#M92806</guid>
      <dc:creator>amaind1990</dc:creator>
      <dc:date>2018-05-11T09:42:29Z</dc:date>
    </item>
    <item>
      <title>Re: Search query taking ages to finish in Splunk 7.0.1</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-query-taking-ages-to-finish-in-Splunk-7-0-1/m-p/309392#M92807</link>
      <description>&lt;P&gt;In my case, I have added "| noop search_optimization=false" at the last line which makes my query fast. You can give a try.&lt;/P&gt;</description>
      <pubDate>Tue, 22 May 2018 05:25:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-query-taking-ages-to-finish-in-Splunk-7-0-1/m-p/309392#M92807</guid>
      <dc:creator>sarfarajsayyad</dc:creator>
      <dc:date>2018-05-22T05:25:52Z</dc:date>
    </item>
    <item>
      <title>Re: Search query taking ages to finish in Splunk 7.0.1</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-query-taking-ages-to-finish-in-Splunk-7-0-1/m-p/309393#M92808</link>
      <description>&lt;P&gt;In my case I have added "| noop search_optimization=false" at the end of the line to resolve the issue. It worked for me, you can give a try. &lt;/P&gt;</description>
      <pubDate>Tue, 22 May 2018 06:08:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-query-taking-ages-to-finish-in-Splunk-7-0-1/m-p/309393#M92808</guid>
      <dc:creator>sarfarajsayyad</dc:creator>
      <dc:date>2018-05-22T06:08:57Z</dc:date>
    </item>
  </channel>
</rss>

