Reporting

Splunk Service Crashes On Exporting Reports On Search Head

shivanshu1593
Builder

Hello All,

I am running Splunk version 7.3.3, and am facing a weird issue where I write a search, which successfully returns all the required values. When I click on export button in the UI to export the data into a CSV, Splunkd crashes on the search head. It doesn't happen with the small sized report, but anything over 800 MB becomes a problem, especially when the data is more than 2 months old.

 

PS: We upgraded from 7.1.X to 7.3 around 2 months ago. It used to work without an issue in the previous version, but now is a problem. 

Any help or suggestions are highly welcomed.

 

Thanks!

Thank you,
Shiv
###If you found the answer helpful, kindly consider upvoting/accepting it as the answer as it helps other Splunkers find the solutions to similar issues###
Labels (2)
0 Karma
1 Solution

shivanshu1593
Builder

Hey @mb1226 ,

I was able to figure this out. To solve this, please traverse to web.conf under $SPLUNK_HOME/etc/system/local and add the following stanza under settings and restart splunkd. It will resolve the issue.

[settings]
export_timeout = 300
splunkdConnectionTimeout = 300

 Problem is that the default value of waiting period is 30 seconds, picked from splunkdConnectionTimeout, if export_timeout is not defined. Usually for large exports, it takes a lot of time. Hence the solution.

Please apply it and let me know if you still encounter the situation.

Thank you,

SN

# If this helps, please mark it as solution or upvote it. It helps other users to find the solution more quickly.

 

 

Thank you,
Shiv
###If you found the answer helpful, kindly consider upvoting/accepting it as the answer as it helps other Splunkers find the solutions to similar issues###

View solution in original post

shivanshu1593
Builder

Hey @mb1226 ,

I was able to figure this out. To solve this, please traverse to web.conf under $SPLUNK_HOME/etc/system/local and add the following stanza under settings and restart splunkd. It will resolve the issue.

[settings]
export_timeout = 300
splunkdConnectionTimeout = 300

 Problem is that the default value of waiting period is 30 seconds, picked from splunkdConnectionTimeout, if export_timeout is not defined. Usually for large exports, it takes a lot of time. Hence the solution.

Please apply it and let me know if you still encounter the situation.

Thank you,

SN

# If this helps, please mark it as solution or upvote it. It helps other users to find the solution more quickly.

 

 

Thank you,
Shiv
###If you found the answer helpful, kindly consider upvoting/accepting it as the answer as it helps other Splunkers find the solutions to similar issues###

mb1226
Explorer

I'm on Splunk 8.1.3 and lately have been having the same problem.   Using Chrome Version 91.0.4472.101,  Any time I try and export a dashboard panel contents , Chrome crashes.   I can restart Chrome and have it reload previous pages, but it is a pain.   If it happens while developing a new search, I can lose latest modifications if I don't remember that the browser will crash.

Anyone have a current fix for this?

0 Karma

richgalloway
SplunkTrust
SplunkTrust
You should open a support request with Splunk.
---
If this reply helps you, Karma would be appreciated.
0 Karma

shivanshu1593
Builder

Hey Rich,

Thanks for answering. I've opened a support ticket already, but as you're aware it takes a bit of time for them to reply and catch up with the issues (No fault of theirs. They have multiple other things to do). I was wondering if anyone in the community had any ideas as to how can we handle this issue 🙂

Thank you,

Thank you,
Shiv
###If you found the answer helpful, kindly consider upvoting/accepting it as the answer as it helps other Splunkers find the solutions to similar issues###
0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...