Splunk Search

Why does my search not finish?

fraser8
Engager

index="king" source ="/King/East"

I am confused why my search doesn't finish. I have a '2 month window' applied to the time.

When I inspect the job I see: This search is still running and is approximately 100% complete.

In the log, the following two items keep repeating every ~5s:

01-29-2018 21:14:25.205 INFO  SortOperator - maxmem = 209715200
01-29-2018 21:14:25.337 INFO  DispatchThread - Generating results preview took 157 ms

When I remove the time filter, and allow for 'All time', the search completes with the output: This search has completed and has returned 16,484 results by scanning 44,750 events in 1.944 seconds

The search that gets stuck:

alt text

1 Solution

acharlieh
Influencer

If you specified to search with a "2 month window" that means you setup a real-time search, which is a continuously executing search.

Instead you want to run a normal historic search (using the "Relative" section of the time range picker) to which the picker would instead read "Last 2 months"

View solution in original post

acharlieh
Influencer

If you specified to search with a "2 month window" that means you setup a real-time search, which is a continuously executing search.

Instead you want to run a normal historic search (using the "Relative" section of the time range picker) to which the picker would instead read "Last 2 months"

somesoni2
Revered Legend

Are you selecting that "2 month window" from Real-time section of time range picker?

0 Karma

fraser8
Engager

Yes, i was selecting Real-time -> 2 Months Ago

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...