Deployment Architecture

Searches are cancelled or time out when user leaves browser window or switches tabs

ITSplunk117
Path Finder

Hello,

We had a customer stumble across this issue recently.  I tried changing the default_auto_cancel from 30 to 62 but after restarting splunkweb I could still pretty much consistently cause searches to be cancelled by switching tabs.  

I checked Edge, Chrome, and Firefox.  On Firefox the issue did not occur.  
My question is there another attribute I could try changing to fix this in Chrome and Edge?  If there isn't an attribute then what browser setting would need to be changed to correct this?

thanks

https://docs.splunk.com/Documentation/Splunk/latest/ReleaseNotes/Knownissues

2021-12-21 SPL-216787


Searches are cancelled or time out when the user leaves the browser window or switches tabs.
 
Workaround:
In Splunk Enterprise 8.1.7, 8.2.4, and higher change the job_default_auto_cancel setting in $SPLUNK_HOME/etc/system/local/web.conf from the default value of 30 to 62

 

 

Labels (1)
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@ITSplunk117 - I would say implement the workaround suggested in the Splunk Doc on the Splunk side.

On the Browser side, I know Crome recently introduced, Power Saving Mode, disable it. That might be causing this issue.

(Check for other browser for similar)

 

I hope this helps!!! Consider upvoting!!!

ITSplunk117
Path Finder

Ok thanks!   If I can still get the searches to auto cancel after changing the auto_cancel value from 30 to 62 then I'm going to have to try disabling Power Saving Mode.  

gunslinger
Explorer

I have both web.conf and chrome configuration updates in place but the issue remains.

As soon as I open something on top of my browser or change tabs, the search auto-cancels.

We've been living with this issue for a few years now hoping for a fix in each of the new releases but still no changes.

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...