Splunk Search

Delay in search time field extractions on search head cluster

ehowardl3
Path Finder

I have a three-node search head cluster, when I create a field extraction through the GUI, it takes hours for it to become active. This used to take less than 5 minutes, any ideas why this could be happening?

Thanks

woodcock
Esteemed Legend

Try adding ... | extract reload=true to your search to pull in the changes immediately, but this only works for you. If you need it to work for everybody, try this app (thanks @mus):
Add-on Debug Refresh: https://splunkbase.splunk.com/app/1871/

0 Karma

ehowardl3
Path Finder

Thanks for the reply @woodcock , however neither ... | extract reload=true nor running a debug refresh works.

0 Karma

woodcock
Esteemed Legend

I would definitely open a support case. Something is VERY not right. Be sure to report back here what you discover.

0 Karma

ehowardl3
Path Finder

Thanks, I'll open a support case and report back.

0 Karma
Get Updates on the Splunk Community!

Tech Talk | Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...

Tech Talk | 3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

Register Join this Tech Talk to learn how unique features like Service Centric Views, Tag Spotlight, and ...

Thank You for Celebrating CX Day with Splunk!

Yesterday the entire team at Splunk + Cisco joined the global celebration of CX Day - celebrating our ...