Splunk Search

Is there a way to add query keyword to a timeout query?

dtakacssplunk
Explorer

I would like to add a keyword in my Splunk queries that would make the query timeout/error after a while (separate from the server setting). Is there such a keyword?

0 Karma

DalJeanis
Legend

As a general case, there is already a length after which search queries will time out.

See the answer here for details about how that works (although the question there is the reverse of yours ) - https://answers.splunk.com/answers/196/how-do-i-increase-the-session-timeout-settings-in-the-config-...

0 Karma

somesoni2
Revered Legend

Whats your requirement here?

0 Karma
Get Updates on the Splunk Community!

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...