Splunk Search

Non-windowed realtime search

mexa
Explorer

On page 62 of the Splunk Search manual, it mentions that: "Windowed real-time searches are more expensive than non-windowed." And: "If your windowed search does not display the expected number of events, try a non-windowed search."

From what I understand, when you specify a time range in the Realtime search query, that makes it a "windowed" search. How do I run a non-windowed search in that case? I am simply interested in reading the newest events coming into the system, without doing any buffering on the server side. I am using the Java SDK for this.

Cheers

Tags (1)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

You'll get a non-windowed realtime search by setting earliest_time=rt and latest_time=rt.

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

You'll get a non-windowed realtime search by setting earliest_time=rt and latest_time=rt.

martin_mueller
SplunkTrust
SplunkTrust

There is a realtime_buffer of 10000 defined in http://docs.splunk.com/Documentation/Splunk/6.0.2/Admin/limitsconf - I'm not sure if that's relevant for you though because that setting mentions splunkweb. There's also a queue_size of 10000, maybe more.

0 Karma

mexa
Explorer

Thanks Martin. Do you know if there is a rate limit for the number of events forwarded to a realtime query?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...