Getting Data In

SPLUNK searches take long to complete.

stanwin
Contributor

Hello Splunkers

The actual time in job inspector seems to not be very long

But usually there is long latency and job inspector logs are stuck at this point..

INFO DispatchThread - Generating results preview took....

11-17-2017 11:32:26.928 INFO  LocalCollector - Final required fields list = _bkt,_cd,_si,_subsecond,host,index,linecount,source,sourcetype,splunk_server
11-17-2017 11:32:26.928 INFO  UserManager - Unwound user context: bondo -> NULL
11-17-2017 11:32:26.928 INFO  UserManager - Setting user context: bondo
11-17-2017 11:32:26.928 INFO  UserManager - Done setting user context: NULL -> bondo
11-17-2017 11:32:26.928 INFO  UserManager - Unwound user context: bondo -> NULL
11-17-2017 11:32:37.438 INFO  DispatchThread - Generating results preview took 1 ms
11-17-2017 11:32:47.441 INFO  DispatchThread - Generating results preview took 1 ms
11-17-2017 11:32:57.444 INFO  DispatchThread - Generating results preview took 1 ms

Are there any tshoot steps for this , perhaps dispatch directory issue etc?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi stanwin,
see in Monitoring Console what's the situation of your Search Heads and Indexers, maybe there's some sofference in executing jobs!
Is your HW infrastructure sufficient for the usual load (Indexing an searching)?

Bye.
Giuseppe

0 Karma

stanwin
Contributor

THanks Cusello for the response!

I was looking for perhaps direct root causes/tshoot areas if any for that specific point/flow in particular.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...