Splunk Search

auto-finalized after time limit ( 30 seconds )

abhayneilam
Contributor

I am getting the following warning while running my big query :

auto-finalized after time limit ( 30 seconds ) reached

can you please let me know what to do if I get this warning, and how does it effect to my query result.and how to increase the time limit for this

0 Karma

marellasunil
Communicator

Or you can use
... |append maxtime=100 [search ... ]

0 Karma

marellasunil
Communicator

The query will finalize its search and you will receive the result till 30 secs only (Not actual result).
If you are having any sub searches, change the time limit in limits.conf (Splunk\etc\system\default\limits.conf).
Hopefully it will work...

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...