Monitoring Splunk

map command returns main index even searching _internal only

mchang_splunk
Splunk Employee
Splunk Employee

I tried to test map command on Splunk 7.1.3 with following search:

index=_internal earliest=-60m | map maxsearches=1 search="search index=_internal  earliest=-6m latest=-1m | head 1"

Theoretically, this search should only return one event from index=_internal.
However, lots of events from main index return

alt text

Is this a bug?

Tags (1)
0 Karma
1 Solution

mchang_splunk
Splunk Employee
Splunk Employee

This is a known issue SPL-167869 and SPL-169704 which will be fixed on 7.3.

Workaround is also available:

add following stanza in ../etc/system/local/limits.conf on SH and restart should fix this issue:

 [search] 
 phased_execution_mode = auto 

After workaround applied:

alt text

View solution in original post

mchang_splunk
Splunk Employee
Splunk Employee

This is a known issue SPL-167869 and SPL-169704 which will be fixed on 7.3.

Workaround is also available:

add following stanza in ../etc/system/local/limits.conf on SH and restart should fix this issue:

 [search] 
 phased_execution_mode = auto 

After workaround applied:

alt text

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...