Reporting

Splunk Service Crashes On Exporting Reports On Search Head

shivanshu1593
Builder

Hello All,

I am running Splunk version 7.3.3, and am facing a weird issue where I write a search, which successfully returns all the required values. When I click on export button in the UI to export the data into a CSV, Splunkd crashes on the search head. It doesn't happen with the small sized report, but anything over 800 MB becomes a problem, especially when the data is more than 2 months old.

 

PS: We upgraded from 7.1.X to 7.3 around 2 months ago. It used to work without an issue in the previous version, but now is a problem. 

Any help or suggestions are highly welcomed.

 

Thanks!

Thank you,
Shiv
###If you found the answer helpful, kindly consider upvoting/accepting it as the answer as it helps other Splunkers find the solutions to similar issues###
Labels (2)
0 Karma
1 Solution

shivanshu1593
Builder

Hey @mb1226 ,

I was able to figure this out. To solve this, please traverse to web.conf under $SPLUNK_HOME/etc/system/local and add the following stanza under settings and restart splunkd. It will resolve the issue.

[settings]
export_timeout = 300
splunkdConnectionTimeout = 300

 Problem is that the default value of waiting period is 30 seconds, picked from splunkdConnectionTimeout, if export_timeout is not defined. Usually for large exports, it takes a lot of time. Hence the solution.

Please apply it and let me know if you still encounter the situation.

Thank you,

SN

# If this helps, please mark it as solution or upvote it. It helps other users to find the solution more quickly.

 

 

Thank you,
Shiv
###If you found the answer helpful, kindly consider upvoting/accepting it as the answer as it helps other Splunkers find the solutions to similar issues###

View solution in original post

shivanshu1593
Builder

Hey @mb1226 ,

I was able to figure this out. To solve this, please traverse to web.conf under $SPLUNK_HOME/etc/system/local and add the following stanza under settings and restart splunkd. It will resolve the issue.

[settings]
export_timeout = 300
splunkdConnectionTimeout = 300

 Problem is that the default value of waiting period is 30 seconds, picked from splunkdConnectionTimeout, if export_timeout is not defined. Usually for large exports, it takes a lot of time. Hence the solution.

Please apply it and let me know if you still encounter the situation.

Thank you,

SN

# If this helps, please mark it as solution or upvote it. It helps other users to find the solution more quickly.

 

 

Thank you,
Shiv
###If you found the answer helpful, kindly consider upvoting/accepting it as the answer as it helps other Splunkers find the solutions to similar issues###

mb1226
Explorer

I'm on Splunk 8.1.3 and lately have been having the same problem.   Using Chrome Version 91.0.4472.101,  Any time I try and export a dashboard panel contents , Chrome crashes.   I can restart Chrome and have it reload previous pages, but it is a pain.   If it happens while developing a new search, I can lose latest modifications if I don't remember that the browser will crash.

Anyone have a current fix for this?

0 Karma

richgalloway
SplunkTrust
SplunkTrust
You should open a support request with Splunk.
---
If this reply helps you, Karma would be appreciated.
0 Karma

shivanshu1593
Builder

Hey Rich,

Thanks for answering. I've opened a support ticket already, but as you're aware it takes a bit of time for them to reply and catch up with the issues (No fault of theirs. They have multiple other things to do). I was wondering if anyone in the community had any ideas as to how can we handle this issue 🙂

Thank you,

Thank you,
Shiv
###If you found the answer helpful, kindly consider upvoting/accepting it as the answer as it helps other Splunkers find the solutions to similar issues###
0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...