Splunk Search

When performing a search splunk web freezes the browser tab and facing performance issue when searching ?

Hemnaath
Motivator

Hi All,

One of the user is facing an performance issue while performing the searches and also the splunk web freezes the browser. User had tried accessing the splunk web from different machine and multiple browser.

We have 3 search head cluster environment with splunk 6.6.1 version.

Question:
How / from where to check the error, specific to this user account and review the performance impact for last 30 days.
How to trouble shoot this issue.

Kindly guide me on this.

0 Karma

dkolekar_splunk
Splunk Employee
Splunk Employee
  1. Check the search query, the user is using to run the search.
  2. If it is a particular SPL is causing the issue, you may need to check the knowledge object and their permissions used in the search query.
  3. Use search artifacts to narrow down the issue. Check search.log and in parallel splunkd.log
  4. Check the job inspector to see where the search is taking a too long time
  5. Using DMC, you can check how many expensive searches a particular user is running. You may need to optimize that.

somesoni2
Revered Legend
0 Karma

Hemnaath
Motivator

Hi Somesoni2, thanks for working on this issue, hey I could see the following error details in the splunkd.log for this particular user who is facing the issue. When checked for a period of last 30 days we could see the below error occurring on and off. Similarly when checked in metrics.log and splunkd_ui_access could not see any error.

Splunkd.log
ERROR AuthenticationManagerLDAP - Couldn't find matching groups for user="user500". Search filter="(&(uniquemember=uid=user500,ou=internal,ou=users,dc=test,dc=com)(cn=Splunk_Admin))" strategy="test LDAP"

So could you please guide me how to fix this issue.
thanks in advance.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...