Knowledge Management

Summary Index: Why is a search that took less time before taking much longer now?

chinmayc469
Explorer

Hello,

I am running a saved search(every 5 min) to populate a summary index using collect command.

Now the search on the summary index is taking too much time to give results. Earlier it was not taking as much time.

What could be the reason for this delay in giving results? Ideally search query on summary index should give results quickly right?

When i searched _internal index for errors, i saw error msg "ERROR IndexScopedSearch - STMgr::distinct_apply_terms failed (rc=-33) while scanning for _indextime bounds in bucket".

Is this error related to my issue?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...