Splunk Search

Long running searches keep timing out

benstraw
Splunk Employee
Splunk Employee

I have several searches that search over all time and they don't seem to finish unless I send them to the background. How can I have these searches complete without sending them to the background?

1 Solution

benstraw
Splunk Employee
Splunk Employee

There will be improvements for this in 4.1, but for now there are a few things you can do. While the long running search is running, click on the jobs link in the top right corner to open the popup jobs manager screen. Your search should be near the top of the list of searches shown there, click the save link, and that will force the job to complete and save a the results data to disk for future use, if you then go back to jobs manager later and click on that search you will be able to get to your search.

You can also try setting a key in web.conf in 4.0.x: poller_timeout_interval, in 4.1 there will be a way to turn the poller off and keep alive for ever, but now in 4.0.x you just need to set a very high number there and that should help things, but depending on your data and your search you may still need to use the save method described above.

View solution in original post

gesman
Communicator

In $SPLUNK_HOME/etc/system/local/web.conf set ui_inactivity_timeout to some higher value, like 1-3 hours or so.
Example:

[settings]
enableSplunkWebSSL = 0
ui_inactivity_timeout = 180

Don't forget to restart Splunk after that.

See more help here:
http://docs.splunk.com/Documentation/Splunk/latest/admin/Webconf

benstraw
Splunk Employee
Splunk Employee

There will be improvements for this in 4.1, but for now there are a few things you can do. While the long running search is running, click on the jobs link in the top right corner to open the popup jobs manager screen. Your search should be near the top of the list of searches shown there, click the save link, and that will force the job to complete and save a the results data to disk for future use, if you then go back to jobs manager later and click on that search you will be able to get to your search.

You can also try setting a key in web.conf in 4.0.x: poller_timeout_interval, in 4.1 there will be a way to turn the poller off and keep alive for ever, but now in 4.0.x you just need to set a very high number there and that should help things, but depending on your data and your search you may still need to use the save method described above.

Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...