Security

Why is browser sluggish when browsing through large raw data events?

dasveruckte
New Member

Does anyone know why I would be getting very bad browsing performance when searching through large events regardless if its on verbose or fast mode. It started happening after the latest Chrome upgrade but it is also happening on Safari and Firefox. We also updated to Splunk 7. No issues with any of the dashboards or searches with stats or visualization on Fast mode.

Thanks in advanced.

0 Karma

landen99
Motivator

All of the data in those raw events is literally stored in the html that the browser has to load.

If this happens with smart mode or fast mode, then your search allows the raw data to be loaded into the Events tab or into a field in the Statistics tab (perhaps an _raw field).

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Automated Threat Analysis: Available in ES Premier

Automated Threat Analysis: Centralize and Accelerate Phishing Investigations in Splunk Enterprise ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...