Splunk Search

What is the difference between run_time and total_run_time?

Taruchit
Contributor

Hello all,

I need help to understand the difference between two fields run_time (fetched from index: _internal) and total_run_time (fetched from index:_audit).

I tried to execute search for same id and for events with same timestamp in the two searches  I observed different values for the two fields.

Any guidance or information will be very helpful.

Thank you

Taruchit

Labels (2)
0 Karma

Taruchit
Contributor

I fetched below threads will have information about the two fields:-

https://community.splunk.com/t5/Splunk-Search/Running-Saved-Searches-with-Default-Index-internal/m-p...

@kristian_kolb shared details about field run_time: How long time it took to execute the search (in seconds)

https://community.splunk.com/t5/Splunk-Search/What-is-this-search-startup-time-in-audit-index/m-p/32...

@splunker12er shared details about field total_run_time: Time in seconds that has been taken for the job to complete

It would be helpful if you could help to elaborate the difference between two fields.

Thank you

0 Karma
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...