Splunk Search

Why does my search not finish?

fraser8
Engager

index="king" source ="/King/East"

I am confused why my search doesn't finish. I have a '2 month window' applied to the time.

When I inspect the job I see: This search is still running and is approximately 100% complete.

In the log, the following two items keep repeating every ~5s:

01-29-2018 21:14:25.205 INFO  SortOperator - maxmem = 209715200
01-29-2018 21:14:25.337 INFO  DispatchThread - Generating results preview took 157 ms

When I remove the time filter, and allow for 'All time', the search completes with the output: This search has completed and has returned 16,484 results by scanning 44,750 events in 1.944 seconds

The search that gets stuck:

alt text

1 Solution

acharlieh
Influencer

If you specified to search with a "2 month window" that means you setup a real-time search, which is a continuously executing search.

Instead you want to run a normal historic search (using the "Relative" section of the time range picker) to which the picker would instead read "Last 2 months"

View solution in original post

acharlieh
Influencer

If you specified to search with a "2 month window" that means you setup a real-time search, which is a continuously executing search.

Instead you want to run a normal historic search (using the "Relative" section of the time range picker) to which the picker would instead read "Last 2 months"

somesoni2
Revered Legend

Are you selecting that "2 month window" from Real-time section of time range picker?

0 Karma

fraser8
Engager

Yes, i was selecting Real-time -> 2 Months Ago

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...