All Apps and Add-ons

Why do I get different performance in Hunk based on how I specify time?


We have a setup with MapR File System and Splunk Hadoop for Analytics (HUNK) ...MapRFS is using an NFS mount to have all logs centralized.

We have our virtual index set up with this file directory format:

I have included the indexes. conf file at the bottom without the provider.

When I run a basic index search such as index=mapr1 | stats count, for the last 3 hours using Splunk Web, it runs optimally. It finds the relevant events quickly and then finished. This is ideal.

When I run the same search for a specific hour in the past (say 3 hours ago) either using the Splunk Web or "earliest=-3h@h latest=-2h@h", it will search through a very large number of events and then find events finally (and its not the correct number of events even).

vix.input.1.accept = = yyyyMMddHH = /user/mapr/maprdata/.?/(\d+)/(\d+)/(\d+)/(\d+)/. = yyyyMMddHH = 3600 = /user/mapr/maprdata/.?/(\d+)/(\d+)/(\d+)/(\d+)/.
vix.input.1.path = /user/mapr/maprdata/${sourcetype}/...
vix.provider = maproly

0 Karma
1 Solution

0 Karma


This was resolved in another question that I asked which can be found here:

0 Karma


are you receiving the data in a json , generated by some application, in that case can you change the timestamp field at the json schema from string to long.
probably your issue is like below:
your Timestamp:
timestamp: "276257257257265"
Splunk expects:
timestamp: 276257257257265

Alternatively, you can handle this via a calculated field. For example, you could add this to props.conf:
EVAL-_time = strptime(timestamp, "%s")
However "%s" expects a 10-digit epoch time string, so you would probably need to use substr/trim too. Hence in this case if possible, it is best to get the timestamp type changed before it reaches splunk.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...