Splunk Search

auto-finalized after time limit ( 30 seconds )


I am getting the following warning while running my big query :

auto-finalized after time limit ( 30 seconds ) reached

can you please let me know what to do if I get this warning, and how does it effect to my query result.and how to increase the time limit for this

0 Karma


Or you can use
... |append maxtime=100 [search ... ]

0 Karma


The query will finalize its search and you will receive the result till 30 secs only (Not actual result).
If you are having any sub searches, change the time limit in limits.conf (Splunk\etc\system\default\limits.conf).
Hopefully it will work...

0 Karma
Get Updates on the Splunk Community!

Index This | A sphere has three, a circle has two, and a point has zero. What is it?

September 2023 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Build Scalable Security While Moving to Cloud - Guide From Clayton Homes

 Clayton Homes faced the increased challenge of strengthening their security posture as they went through ...

Mission Control | Explore the latest release of Splunk Mission Control (2.3)

We’re happy to announce the release of Mission Control 2.3 which includes several new and exciting features ...