Splunk Search

What is the unit of time for run_time ?

the_wolverine
Champion

Would someone please confirm what the unit of time reported by run_time is? Run_time as reported by the scheduler or by jobs.

Tags (2)
0 Karma
1 Solution

yannK
Splunk Employee
Splunk Employee

if this is a run time like this from the scheduler.log , run_time is likely in seconds

run_time=0.847 => zero seconds and 847 milliseconds.

05-24-2012 15:01:12.571 -0700 INFO SavedSplunker - savedsearch_id="nobody;webintelligence;Referer breakdown fivemin summary - regenerator", user="nobody", app="webintelligence", savedsearch_name="Referer breakdown fivemin summary - regenerator", status=success, digest_mode=1, scheduled_time=1337896800, dispatch_time=1337896871, run_time=0.847, result_count=0, alert_actions="summary_index", sid="scheduler__nobody__webintelligence_UmVmZXJlciBicmVha2Rvd24gZml2ZW1pbiBzdW1tYXJ5IC0gcmVnZW5lcmF0b3I_at_1337896800_c1cad5102813ad2e", suppressed=0, thread_id="AlertNotifierWorker-0"

View solution in original post

0 Karma

yannK
Splunk Employee
Splunk Employee

if this is a run time like this from the scheduler.log , run_time is likely in seconds

run_time=0.847 => zero seconds and 847 milliseconds.

05-24-2012 15:01:12.571 -0700 INFO SavedSplunker - savedsearch_id="nobody;webintelligence;Referer breakdown fivemin summary - regenerator", user="nobody", app="webintelligence", savedsearch_name="Referer breakdown fivemin summary - regenerator", status=success, digest_mode=1, scheduled_time=1337896800, dispatch_time=1337896871, run_time=0.847, result_count=0, alert_actions="summary_index", sid="scheduler__nobody__webintelligence_UmVmZXJlciBicmVha2Rvd24gZml2ZW1pbiBzdW1tYXJ5IC0gcmVnZW5lcmF0b3I_at_1337896800_c1cad5102813ad2e", suppressed=0, thread_id="AlertNotifierWorker-0"

0 Karma

the_wolverine
Champion

Yes, it does appear to be in seconds. We had a few searches that were taking so long to complete that I couldn't believe that the number I was looking at was in seconds!

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...