I am running 5.0.1 on Ubuntu Server Every so often we get a stuck Report Acceleration Summarize search. For example, here is one from the Jobs page:
Dispatched at Owner Application Size Events Run time Expires Status
1/21/13 11:57:35 PM splunk-system-user system 0.06MB 0 00:00:01 Jan 22, 2013 12:19:42 PM Running (0%)
The search shown is | summarize maintain="CA731B2B-5B97-408C-943F-C96771D302E9_SplunkDirectoryServices_username_5d7d2aa78b3ac0e4,1358784000;CA731B2B-5B97-408C-943F-C96771D302E9_search_username_3bfa8a40a0cd07e5,1358784000;" summaryprefix="CA731B2B-5B97-408C-943F-C96771D302E9"
These searches cause CPU usage of >90% while they are running, and they don't end. To solve it, we just kill the job process from the server.
I inspected the job, and looked at the search.log. At the very end, there is this:
01-21-2013 23:57:37.331 INFO UserManager - Unwound user context: splunk-system-user -> NULL
01-21-2013 23:57:37.333 INFO DispatchCommand - Round Robin Threaded ProviderQueue: done reading from peer 'INDXR1'
Any ideas?
I have since changed jobs, and I had opened a support case. Nothing concrete from before I left there.
I have since changed jobs, and I had opened a support case. Nothing concrete from before I left there.
Did you open a support case? We probably need more information.