Splunk Search

I have no queued tasks but my search is still queued?

Cuicuo
Engager
I found that I am the only user who has this situation. My role is admin. I thought it was a performance problem, but after solving the performance problem, I still can't run the real-time search, but the scheduled search can run. How do I get myself to run a real-time search?

 

 

Labels (1)
0 Karma
1 Solution

Manasa_401
Communicator

Hello @Cuicuo 

This could be probably due to disk usage quota for your role.  Use the JobManager to delete some of your search artifacts, or increase the disk quota of search artifacts for your role in authorize.conf and make the changes.

Thanks

Manasa

View solution in original post

Manasa_401
Communicator

Hello @Cuicuo 

This could be probably due to disk usage quota for your role.  Use the JobManager to delete some of your search artifacts, or increase the disk quota of search artifacts for your role in authorize.conf and make the changes.

Thanks

Manasa

Cuicuo
Engager

Thank you Manasa!!  It works and I can run the search without any problem now.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Cuicuo,

the indication from @Manasa_401 is correct,

in addition, check (using Monitoring Console) if you have some scheduled searches that full your queue.

Ciao.

Giuseppe

Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...