Splunk Search

Search Application Summary page slow to load

gfriedmann
Communicator

We index data from about 2000 different hosts. logs are relayed in via a TCP syslog source.

Whenever a user goes to the search application, it takes a good 20+ seconds to load all the summary dada, such as Events Indexed" and all of the counts for each source & host.

Is there any way to edit this page or speed up this search or used cached results on a 5 minute schedule or something like that? The lag really gives an impression of system slowness on this very first page. 😕

0 Karma
1 Solution

Brian_Osburn
Builder

I had the same problem. My solution was to remove the searches from the summary page, which was a big improvement.

View solution in original post

0 Karma

Brian_Osburn
Builder

I had the same problem. My solution was to remove the searches from the summary page, which was a big improvement.

0 Karma

Simeon
Splunk Employee
Splunk Employee

The searches run from the summary page are metadata searches. These should run very quickly. The comparable search queries would be:

| metadata type=hosts

| metadata type=sources

| metadata type=sourcetypes

Each of the above searches should only take a few seconds to return. It is possible that you have a performance problem that is causing these searches to run slowly. In that case, I recommend you contact support to help debug the problem.

If you are in a distributed search environment, it is possible that the remote peers are taking a while to return data. Splunk will wait to compile all of the results from each indexer before painting the page.

0 Karma
Get Updates on the Splunk Community!

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...