Getting Data In

Splunk 6 REST API: Much slower than 5

twinspop
Influencer

I upgraded our indexers to Splunk 6 about 3 weeks ago. Our monitoring scripts use the REST interface to hit Splunk. Since the upgrade, calls to the REST API have slowed considerably. (Showing 95th % search run time for the REST API user.)

Anyone else notice similar?

I'm just starting the investigation. (Didn't notice til this morning - doh!) Pointers to likely sources of the delay appreciated.

Tags (3)
0 Karma

dball2
New Member

I have a similar problem, a query in the UI is taking around 10sec, and via searches export it takes > 4mins. Using splunk cloud API.

Incredibly slow. Someone should look at that .

0 Karma

ineeman
Splunk Employee
Splunk Employee

What OS are you running on? Also, the UI ends up using the API as well, so it is odd it is much faster in the UI. In the search inspector for both jobs (ones started from the UI and ones from the API), do you see any marked difference, especially in the 'request' field (which should be a JSON dictionary)?

0 Karma

austremestephen
New Member

version 6 API response is very slow compared with version 5.

0 Karma

twinspop
Influencer

For the record: In the case of one of my saved searches, I can run the exact same search through the GUI on the exact same indexer and get an answer back in 1.5s. If I use the API, the response takes 25-30s.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...