Splunk Search

Why can I not search in Smart Mode or Verbose Mode in a specific sourcetype?

matthewssa
Path Finder

Hi!

I am trying to perform a very basic search to bring back results but the search appears to never finish when I queue it up for a specific index and sourcetype in either Smart Mode or Verbose Mode. What is puzzling is the results are only 601 events which is not much at all. I have checked other sourcetypes in the same index and they appear to be working with no issue when running them in Smart Mode and Verbose Mode.

This search will not finish in either Smart Mode or Verbose Mode Last 15 minutes:

index=bro sourcetype=bro_smtp

This search will finish in Fast Mode Last 15 minutes: Results 601 events.

index=bro sourcetype=bro_smtp
0 Karma
1 Solution

micahkemp
Champion

I bet you have a regex that is misbehaving. Did you recently add a search time extraction? If so, what does the regex look like?

I've had this happen a few times when a regex wasn't specific enough and would essentially have infinite matches or possible matches.

View solution in original post

micahkemp
Champion

I bet you have a regex that is misbehaving. Did you recently add a search time extraction? If so, what does the regex look like?

I've had this happen a few times when a regex wasn't specific enough and would essentially have infinite matches or possible matches.

matthewssa
Path Finder

I did pull over the same Bro app that has all of our parsing inside the app from another one of our Splunk instances. I commented out all of the entries in our transforms.conf file in the Bro app on one of our indexers and tried to search the field bro_smtp in verbose mode and what do you know! It works! I guess now I just need to go back through and figure out which one broke that sourcetype. Thanks!

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...