Splunk Search

Search Application Summary page slow to load

gfriedmann
Communicator

We index data from about 2000 different hosts. logs are relayed in via a TCP syslog source.

Whenever a user goes to the search application, it takes a good 20+ seconds to load all the summary dada, such as Events Indexed" and all of the counts for each source & host.

Is there any way to edit this page or speed up this search or used cached results on a 5 minute schedule or something like that? The lag really gives an impression of system slowness on this very first page. 😕

0 Karma
1 Solution

Brian_Osburn
Builder

I had the same problem. My solution was to remove the searches from the summary page, which was a big improvement.

View solution in original post

0 Karma

Brian_Osburn
Builder

I had the same problem. My solution was to remove the searches from the summary page, which was a big improvement.

0 Karma

Simeon
Splunk Employee
Splunk Employee

The searches run from the summary page are metadata searches. These should run very quickly. The comparable search queries would be:

| metadata type=hosts

| metadata type=sources

| metadata type=sourcetypes

Each of the above searches should only take a few seconds to return. It is possible that you have a performance problem that is causing these searches to run slowly. In that case, I recommend you contact support to help debug the problem.

If you are in a distributed search environment, it is possible that the remote peers are taking a while to return data. Splunk will wait to compile all of the results from each indexer before painting the page.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...