Monitoring Splunk

monitor performance or Debug splunk queries

adityapavan18
Contributor

Hi,

Is there any way i can monitor how much time is being taken for query to execute and also which part of query is taking more time.

And also is there anyway to debug queries to check where the query is failing.

Thanks

Tags (3)
0 Karma

yong_ly
Path Finder

Hi, I know this is an old thread but for anyone who might stumble upon this. You can inspect the query via the "Job Inspector". There's a button on the search screen after the search is completed which will give you details on the job. It's quite useful for determining how long a specific search takes and what parts of it took so long.

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi adityapavan

did you try the SOS app http://splunk-base.splunk.com/apps/29008/sos-splunk-on-splunk maybe you find what your looking for in this app.
beside the SOS app, you can find many information regarding performance inside your _internal index and specific in the metrics.log

cheers

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Request for Professional Development: Attending .conf26

Winning Over the Boss: Your Pass to .conf26 conf26 is going to be here before you know it. If don't already ...

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...