Knowledge Management

Splunk-system-user Report Acceleration Search Stuck

alacercogitatus
SplunkTrust
SplunkTrust

I am running 5.0.1 on Ubuntu Server Every so often we get a stuck Report Acceleration Summarize search. For example, here is one from the Jobs page:

Dispatched at Owner Application Size Events Run time Expires Status
1/21/13 11:57:35 PM splunk-system-user system 0.06MB 0 00:00:01 Jan 22, 2013 12:19:42 PM Running (0%)

The search shown is | summarize maintain="CA731B2B-5B97-408C-943F-C96771D302E9_SplunkDirectoryServices_username_5d7d2aa78b3ac0e4,1358784000;CA731B2B-5B97-408C-943F-C96771D302E9_search_username_3bfa8a40a0cd07e5,1358784000;" summaryprefix="CA731B2B-5B97-408C-943F-C96771D302E9"

These searches cause CPU usage of >90% while they are running, and they don't end. To solve it, we just kill the job process from the server.

I inspected the job, and looked at the search.log. At the very end, there is this:

01-21-2013 23:57:37.331 INFO UserManager - Unwound user context: splunk-system-user -> NULL
01-21-2013 23:57:37.333 INFO DispatchCommand - Round Robin Threaded ProviderQueue: done reading from peer 'INDXR1'

Any ideas?

1 Solution

alacercogitatus
SplunkTrust
SplunkTrust

I have since changed jobs, and I had opened a support case. Nothing concrete from before I left there.

View solution in original post

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

I have since changed jobs, and I had opened a support case. Nothing concrete from before I left there.

0 Karma

araitz
Splunk Employee
Splunk Employee

Did you open a support case? We probably need more information.

0 Karma
Get Updates on the Splunk Community!

Changes to Splunk Instructor-Led Training Completion Criteria

We’re excited to share an update to our instructor-led training program that enhances the learning experience ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

❄️ Welcome the new year with our January lineup of Community Office Hours, Tech Talks, and Webinars! 🎉 ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...