Splunk Search

Search auto-finalized after time limit (30 seconds) reached on running SubSearch

ChhayaV
Communicator

Hi,

I have a search query which includes subsearch as follows:

host="sharepoint"  | rex field=msg "\sMore\sinformation:\s(?<EventCode>[\dxA-F]+)" | rename EventCode as output | eventstats count by output | sort -count | dedup output | append [search host="database" | rename EventCode as output | eventstats count by output | dedup output | sort -count | head 5] | table output count | sort -count

When i run this search it says :

[subsearch]: Search auto-finalized after time limit (30 seconds) reached

I checked my limit.conf file and its subsearch parameters as

[subsearch]
maxout = 10000
maxtime = 60
ttl = 300

So what's needs to be changed ?
Is there are any changes to be made in limits.conf file?
How to come out of this problem.Also here my search is taking to long to process(taking more time).

Thank you

Tags (1)

HiroshiSatoh
Champion

HiroshiSatoh
Champion

Do not have effect options append command? It has become the default is 60 in the document ...

ex.
・・・・ append maxtime=60 [search host="database" ・・・・・

0 Karma

ChhayaV
Communicator

Yes,this issue is similar to that event.Is it so if we use "Append" in subsearch will set the default time to 30sec?
What would be the solution for this?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...