Splunk Search

New search button is really slow

sixcorners
Loves-to-Learn

When I click new search in the context menu it opens a new tab with a search with the single field I click on.
The new search looks something like this:
*| spath severity | search severity=DEBUG
This is super slow. Is there a way to make this faster?

Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Where is this context menu?
Is * really the first part of the search?

---
If this reply helps you, an upvote would be appreciated.
0 Karma

sixcorners
Loves-to-Learn

This is the context menu. It appears when clicking on absolutely any value when using splunk to search logs. The queries it produces are really slow.

sixcorners_0-1635266653386.png

 

0 Karma

sixcorners
Loves-to-Learn

yes * is really the first part of the search
Is this not a search option that everyone has?

0 Karma

sixcorners
Loves-to-Learn

The context menu appears when I'm on the search results page. If I click on one of the event's values like ERROR in severity: ERROR then the context menu appears and gives three options. "Add to search", "Exclude from search", and "New search" with little icons that will open it in a new tab.
I guess it's under itsi. Here is the URL path:
/en-US/app/itsi/search

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!