Splunk Enterprise Security

Why does the startup.handoff for searches from our Splunk App for Enterprise Security search head seem to take a long time?

Explorer

Searches from our Enterprise Security search head seem to take a long time to handoff. How long?

15 -16 seconds.

Search is a simple "index=_internal earliest=-10m"

Splunk 6.1.6. Clustered indexers.

Splunk Employee
Splunk Employee

How many jobs do you have at the same time ? How many CPU do you have ?

Contributor

This isnt an answer...

0 Karma

Splunk Employee
Splunk Employee

No, but with the lack of details you gave, it's not easy to give you a good answer !

Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes and swag!