Splunk Search

Search times out from UI or CLI.

New Member

My installation of Splunk (ver 3.4.6) is stalling out during any type of search; including just loading a default dashboard. Is this the 2010 date issue catching up with me? I have restarted the server and the splunk service several times.

Tags (2)
0 Karma

Splunk Employee
Splunk Employee

You would probably find it very beneficial to migrate up to version 4.x from 3.4.6 as well.

0 Karma

Splunk Employee
Splunk Employee

There are various reasons why a search may not return, but typically they can stem from the following:

  • the search query does not span the right data or timerange
  • the data does not exist (it's surprising how often this happens)
  • there is a problem with the indexes in some way

If you have run wild card searches that span all time ranges for all indexes (including _internal) and receive no results, then I suspect you have a problem with the indexes. For this situation you should log a case with Splunk support.

Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!