Monitoring Splunk

monitor performance or Debug splunk queries

adityapavan18
Contributor

Hi,

Is there any way i can monitor how much time is being taken for query to execute and also which part of query is taking more time.

And also is there anyway to debug queries to check where the query is failing.

Thanks

Tags (3)
0 Karma

yong_ly
Path Finder

Hi, I know this is an old thread but for anyone who might stumble upon this. You can inspect the query via the "Job Inspector". There's a button on the search screen after the search is completed which will give you details on the job. It's quite useful for determining how long a specific search takes and what parts of it took so long.

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi adityapavan

did you try the SOS app http://splunk-base.splunk.com/apps/29008/sos-splunk-on-splunk maybe you find what your looking for in this app.
beside the SOS app, you can find many information regarding performance inside your _internal index and specific in the metrics.log

cheers

Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...