Getting Data In

Different search performance for two sourcetype

pradeepchhetri
Engager

Hi,

We have a splunk machine running with all the events going to one index. I noticed that for two different sourcetype, I got different search performance. For one of the sourcetype, searching happened very quickly but it was very slow for the other. Can someone explain me why i am getting such a difference.

Regards.

Tags (2)
0 Karma
1 Solution

MuS
Legend

Hi pradeepchhetri,

This is the kind of question, that is almost impossible for anyone to answer, except to you - because you know your setup, know your events, know your server's load and so on.....

here are some basic troubleshooting things:

  • do both sourcetypes have exactly the same event count over the exact same time range?
  • is your search head / indexer over loaded?
  • are there any saved searches running?
  • check the job inspector to get any idea why one search is running slower as the other.

you see, there is a lot to check for you.

cheers, MuS

View solution in original post

MuS
Legend

Hi pradeepchhetri,

This is the kind of question, that is almost impossible for anyone to answer, except to you - because you know your setup, know your events, know your server's load and so on.....

here are some basic troubleshooting things:

  • do both sourcetypes have exactly the same event count over the exact same time range?
  • is your search head / indexer over loaded?
  • are there any saved searches running?
  • check the job inspector to get any idea why one search is running slower as the other.

you see, there is a lot to check for you.

cheers, MuS

pradeepchhetri
Engager

@Mus: @martin_mueller: Just realized that the difference was due to fast-mode and smart-mode search types, although both has same number of events. Thank you for the help.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

I'm going to guess that production will have much more data than staging.

0 Karma

pradeepchhetri
Engager

@Mus: Thank you for the reply. I will do the troubleshooting accordingly and let you know the outcome.

0 Karma

pradeepchhetri
Engager

my search query just includes: sourcetype="production" and sourcetype="staging"

0 Karma

splunker12er
Motivator

Can you post your search query ?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...