Splunk Search

Why does my search not finish?

fraser8
Engager

index="king" source ="/King/East"

I am confused why my search doesn't finish. I have a '2 month window' applied to the time.

When I inspect the job I see: This search is still running and is approximately 100% complete.

In the log, the following two items keep repeating every ~5s:

01-29-2018 21:14:25.205 INFO  SortOperator - maxmem = 209715200
01-29-2018 21:14:25.337 INFO  DispatchThread - Generating results preview took 157 ms

When I remove the time filter, and allow for 'All time', the search completes with the output: This search has completed and has returned 16,484 results by scanning 44,750 events in 1.944 seconds

The search that gets stuck:

alt text

1 Solution

acharlieh
Influencer

If you specified to search with a "2 month window" that means you setup a real-time search, which is a continuously executing search.

Instead you want to run a normal historic search (using the "Relative" section of the time range picker) to which the picker would instead read "Last 2 months"

View solution in original post

acharlieh
Influencer

If you specified to search with a "2 month window" that means you setup a real-time search, which is a continuously executing search.

Instead you want to run a normal historic search (using the "Relative" section of the time range picker) to which the picker would instead read "Last 2 months"

somesoni2
Revered Legend

Are you selecting that "2 month window" from Real-time section of time range picker?

0 Karma

fraser8
Engager

Yes, i was selecting Real-time -> 2 Months Ago

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...