Splunk Search

What happens to an incomplete search run on one dashboard, but the user changes to another dashboard?

Lucas_K
Motivator

What happens when a search that is kicked off by a dashboard but is then abandoned by the user? ie. they change to another dashboard etc? How does this interact with a distributed environment?

Does the splunkweb process realise that there is no web interface to send the results back to and sends the search peers a signal to stop the searches or do they continue to run until complete? If so it seems like there is plenty of potential for wasted resources.

1 Solution

gkanapathy
Splunk Employee
Splunk Employee

Unless a search is explicitly sent to the background, it is killed when the UI page that dispatched it is no longer connecting to SplunkWeb and Splunkd. Backgrounded searches continue to run, as that is the point of sending a search to the background.

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

Unless a search is explicitly sent to the background, it is killed when the UI page that dispatched it is no longer connecting to SplunkWeb and Splunkd. Backgrounded searches continue to run, as that is the point of sending a search to the background.

Lucas_K
Motivator

Thanks. You were the exact person I was hoping would answer. It was something i'd always wondered and figured I'd be able to probably tell from internal logs but thought i'd just ask 🙂

Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...