Splunk Search

Long running searches keep timing out

benstraw
Splunk Employee
Splunk Employee

I have several searches that search over all time and they don't seem to finish unless I send them to the background. How can I have these searches complete without sending them to the background?

1 Solution

benstraw
Splunk Employee
Splunk Employee

There will be improvements for this in 4.1, but for now there are a few things you can do. While the long running search is running, click on the jobs link in the top right corner to open the popup jobs manager screen. Your search should be near the top of the list of searches shown there, click the save link, and that will force the job to complete and save a the results data to disk for future use, if you then go back to jobs manager later and click on that search you will be able to get to your search.

You can also try setting a key in web.conf in 4.0.x: poller_timeout_interval, in 4.1 there will be a way to turn the poller off and keep alive for ever, but now in 4.0.x you just need to set a very high number there and that should help things, but depending on your data and your search you may still need to use the save method described above.

View solution in original post

gesman
Communicator

In $SPLUNK_HOME/etc/system/local/web.conf set ui_inactivity_timeout to some higher value, like 1-3 hours or so.
Example:

[settings]
enableSplunkWebSSL = 0
ui_inactivity_timeout = 180

Don't forget to restart Splunk after that.

See more help here:
http://docs.splunk.com/Documentation/Splunk/latest/admin/Webconf

benstraw
Splunk Employee
Splunk Employee

There will be improvements for this in 4.1, but for now there are a few things you can do. While the long running search is running, click on the jobs link in the top right corner to open the popup jobs manager screen. Your search should be near the top of the list of searches shown there, click the save link, and that will force the job to complete and save a the results data to disk for future use, if you then go back to jobs manager later and click on that search you will be able to get to your search.

You can also try setting a key in web.conf in 4.0.x: poller_timeout_interval, in 4.1 there will be a way to turn the poller off and keep alive for ever, but now in 4.0.x you just need to set a very high number there and that should help things, but depending on your data and your search you may still need to use the save method described above.

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...