Getting Data In

Different search performance for two sourcetype

pradeepchhetri
Engager

Hi,

We have a splunk machine running with all the events going to one index. I noticed that for two different sourcetype, I got different search performance. For one of the sourcetype, searching happened very quickly but it was very slow for the other. Can someone explain me why i am getting such a difference.

Regards.

Tags (2)
0 Karma
1 Solution

MuS
SplunkTrust
SplunkTrust

Hi pradeepchhetri,

This is the kind of question, that is almost impossible for anyone to answer, except to you - because you know your setup, know your events, know your server's load and so on.....

here are some basic troubleshooting things:

  • do both sourcetypes have exactly the same event count over the exact same time range?
  • is your search head / indexer over loaded?
  • are there any saved searches running?
  • check the job inspector to get any idea why one search is running slower as the other.

you see, there is a lot to check for you.

cheers, MuS

View solution in original post

MuS
SplunkTrust
SplunkTrust

Hi pradeepchhetri,

This is the kind of question, that is almost impossible for anyone to answer, except to you - because you know your setup, know your events, know your server's load and so on.....

here are some basic troubleshooting things:

  • do both sourcetypes have exactly the same event count over the exact same time range?
  • is your search head / indexer over loaded?
  • are there any saved searches running?
  • check the job inspector to get any idea why one search is running slower as the other.

you see, there is a lot to check for you.

cheers, MuS

pradeepchhetri
Engager

@Mus: @martin_mueller: Just realized that the difference was due to fast-mode and smart-mode search types, although both has same number of events. Thank you for the help.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

I'm going to guess that production will have much more data than staging.

0 Karma

pradeepchhetri
Engager

@Mus: Thank you for the reply. I will do the troubleshooting accordingly and let you know the outcome.

0 Karma

pradeepchhetri
Engager

my search query just includes: sourcetype="production" and sourcetype="staging"

0 Karma

splunker12er
Motivator

Can you post your search query ?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...