Splunk Search

command.search.kv performance

rettops
Path Finder

We have a search that is spending most of its time in command.search.kv. If we give it a search which doesn't need any fields, like:

index=myindex sourcetype=mytype | stats count

it takes 1.8 seconds to count the 104,000 events (that alone seems high).

If instead we give it any search which would cause it to extract fields, e.g.:

index=myindex sourcetype=mytype myfield=val1 | stats count

then the time jumps up to 9 seconds, almost all of which is in command.search.kv.

We have no custom field extractions, field transformations, field aliases or tags. Each data item does have 101 fields, but the search in question really only needs 8 of them. Is there any way to speed things up? For example, is there a way to tell Splunk to turn off all of the automatic field extractions and have it use only some user defined ones? Alternatively, is there any way to debug what's happening during command.search.kv?

Tags (1)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

You can set KV_MODE to none in props.conf to turn off automatic extraction of key-value pairs.

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

You can set KV_MODE to none in props.conf to turn off automatic extraction of key-value pairs.

landen99
Motivator

Extractions only happen for fields needed by the search.

0 Karma

rettops
Path Finder

I forgot to mention - the 9 seconds is in 'fast' mode search. In verbose mode it jumps to 18 seconds.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...