Getting Data In

SPLUNK searches take long to complete.

stanwin
Contributor

Hello Splunkers

The actual time in job inspector seems to not be very long

But usually there is long latency and job inspector logs are stuck at this point..

INFO DispatchThread - Generating results preview took....

11-17-2017 11:32:26.928 INFO  LocalCollector - Final required fields list = _bkt,_cd,_si,_subsecond,host,index,linecount,source,sourcetype,splunk_server
11-17-2017 11:32:26.928 INFO  UserManager - Unwound user context: bondo -> NULL
11-17-2017 11:32:26.928 INFO  UserManager - Setting user context: bondo
11-17-2017 11:32:26.928 INFO  UserManager - Done setting user context: NULL -> bondo
11-17-2017 11:32:26.928 INFO  UserManager - Unwound user context: bondo -> NULL
11-17-2017 11:32:37.438 INFO  DispatchThread - Generating results preview took 1 ms
11-17-2017 11:32:47.441 INFO  DispatchThread - Generating results preview took 1 ms
11-17-2017 11:32:57.444 INFO  DispatchThread - Generating results preview took 1 ms

Are there any tshoot steps for this , perhaps dispatch directory issue etc?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi stanwin,
see in Monitoring Console what's the situation of your Search Heads and Indexers, maybe there's some sofference in executing jobs!
Is your HW infrastructure sufficient for the usual load (Indexing an searching)?

Bye.
Giuseppe

0 Karma

stanwin
Contributor

THanks Cusello for the response!

I was looking for perhaps direct root causes/tshoot areas if any for that specific point/flow in particular.

0 Karma
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...