Splunk Search

What is the unit of time for run_time ?

the_wolverine
Champion

Would someone please confirm what the unit of time reported by run_time is? Run_time as reported by the scheduler or by jobs.

Tags (2)
0 Karma
1 Solution

yannK
Splunk Employee
Splunk Employee

if this is a run time like this from the scheduler.log , run_time is likely in seconds

run_time=0.847 => zero seconds and 847 milliseconds.

05-24-2012 15:01:12.571 -0700 INFO SavedSplunker - savedsearch_id="nobody;webintelligence;Referer breakdown fivemin summary - regenerator", user="nobody", app="webintelligence", savedsearch_name="Referer breakdown fivemin summary - regenerator", status=success, digest_mode=1, scheduled_time=1337896800, dispatch_time=1337896871, run_time=0.847, result_count=0, alert_actions="summary_index", sid="scheduler__nobody__webintelligence_UmVmZXJlciBicmVha2Rvd24gZml2ZW1pbiBzdW1tYXJ5IC0gcmVnZW5lcmF0b3I_at_1337896800_c1cad5102813ad2e", suppressed=0, thread_id="AlertNotifierWorker-0"

View solution in original post

0 Karma

yannK
Splunk Employee
Splunk Employee

if this is a run time like this from the scheduler.log , run_time is likely in seconds

run_time=0.847 => zero seconds and 847 milliseconds.

05-24-2012 15:01:12.571 -0700 INFO SavedSplunker - savedsearch_id="nobody;webintelligence;Referer breakdown fivemin summary - regenerator", user="nobody", app="webintelligence", savedsearch_name="Referer breakdown fivemin summary - regenerator", status=success, digest_mode=1, scheduled_time=1337896800, dispatch_time=1337896871, run_time=0.847, result_count=0, alert_actions="summary_index", sid="scheduler__nobody__webintelligence_UmVmZXJlciBicmVha2Rvd24gZml2ZW1pbiBzdW1tYXJ5IC0gcmVnZW5lcmF0b3I_at_1337896800_c1cad5102813ad2e", suppressed=0, thread_id="AlertNotifierWorker-0"

0 Karma

the_wolverine
Champion

Yes, it does appear to be in seconds. We had a few searches that were taking so long to complete that I couldn't believe that the number I was looking at was in seconds!

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...