Splunk Search

What is causing my Activity Jobs pages to be filled with subsearch entries and how do I stop this?

landen99
Motivator

Currently, I have 12.5 pages filled completely with searches which look exactly like:

| subsearch

Many of those entries appear to have the exact same Size and their run time are all 1s. Also, clicking on any of the subsearch search links brings a search page with the same lookup table displayed.

What is causing all of these ambiguous searches? How can I stop them from flooding my Job pages?

gkanapathy
Splunk Employee
Splunk Employee

I'm guessing you have a realtime search that includes a subsearch as part of the RT search.

landen99
Motivator

I found and dealt with the rt searches. The number of subsearch entries greatly reduced (down to 2 entries on the first page), but I am still interested in why these entries exist? What useful value can these entries provide to me when I am looking through my search history? How can I determine whether the rt searches were the cause or if the reduction in subsearch entries is just a coincidence?

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...