Splunk Search

Splunk Ad-hoc search getting auto-cancelled randomly

sagaraverma
Loves-to-Learn Everything

My Ad-hoc searches getting auto-cancelled randomly.
I am running them with admin privileges.
There's no problem with RAM.
DO not have any limits.conf or authorize.conf under system/local

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

what you found when you are looking job inspection?

r. Ismo

0 Karma

sagaraverma
Loves-to-Learn Everything

Nothing important into inspection search logs .

A single line that differs into successful and unsuccessful run is -

ReducedPhaseExecution status=failed 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Have you SH or SHC?

Any errors in internal logs?

0 Karma

sagaraverma
Loves-to-Learn Everything

Stand-alone SH connected to clustered search peers

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Have you tried to send a job to background? Is it working or not on that way?
Is there FW or some other network equipments between sh and IDX cluster? 

What is latency and realibilty between nodes?

0 Karma

sagaraverma
Loves-to-Learn Everything

No such message around error that can expose some hint ..and that’s really strange.

I suspect some kind of limit is getting applied via limits.conf from system/default since we do not have any set under system/local but then there hundreds of default limits and no clue for which one should be looked at ..

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...