Splunk Search

Why can I not search in Smart Mode or Verbose Mode in a specific sourcetype?

matthewssa
Path Finder

Hi!

I am trying to perform a very basic search to bring back results but the search appears to never finish when I queue it up for a specific index and sourcetype in either Smart Mode or Verbose Mode. What is puzzling is the results are only 601 events which is not much at all. I have checked other sourcetypes in the same index and they appear to be working with no issue when running them in Smart Mode and Verbose Mode.

This search will not finish in either Smart Mode or Verbose Mode Last 15 minutes:

index=bro sourcetype=bro_smtp

This search will finish in Fast Mode Last 15 minutes: Results 601 events.

index=bro sourcetype=bro_smtp
0 Karma
1 Solution

micahkemp
Champion

I bet you have a regex that is misbehaving. Did you recently add a search time extraction? If so, what does the regex look like?

I've had this happen a few times when a regex wasn't specific enough and would essentially have infinite matches or possible matches.

View solution in original post

micahkemp
Champion

I bet you have a regex that is misbehaving. Did you recently add a search time extraction? If so, what does the regex look like?

I've had this happen a few times when a regex wasn't specific enough and would essentially have infinite matches or possible matches.

matthewssa
Path Finder

I did pull over the same Bro app that has all of our parsing inside the app from another one of our Splunk instances. I commented out all of the entries in our transforms.conf file in the Bro app on one of our indexers and tried to search the field bro_smtp in verbose mode and what do you know! It works! I guess now I just need to go back through and figure out which one broke that sourcetype. Thanks!

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...