Dashboards & Visualizations

Search is waiting for Input on dashboard stuck for quite long

vishaltaneja070
Motivator

In one of servers, we are getting search is waiting warning for quite long time. It takes around 10 seconds after that it will be loaded.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi vishaltaneja07011993,
use Monitoring Console to check if your hardware configuration is correctly dimensionated (12 CPUs and 12GB of RAM at least) and if there are scheduled searches that overload your system.
Remember that every search and subsearch takes a CPU, so if you execute a dashboard with 6 panels with a main search and 3 subsearches for each, you are using 24 CPUs that are released only when the search is finished, if more users use the same dashboard you can understand the problem!
Additional problems there are if you're using Real Time Searches because they don't release CPUs.

Bye.
Giuseppe

0 Karma

vishaltaneja070
Motivator

Even sometimes, no saved search specified as well.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...