Hi Folks, From last couple of weeks we have observed an issue in our newly developed Splunk app(Radware Bot Risk Scanner ). our app schedules a saved search which runs every hour and extract some data from indices and forwards to custom search command which we developed and saves the result in result indices. Flow: Splunk Search -> Custom Search Command (which preforms REST API call for each record) -> save result to new indice. Saved Searches got stuck in Running state. when I try to stop it manually, its going to Finalizing state not done state. Ideal time for this saved search to finish is ~2mins including all Rest API calls, yet you can see often its running from a very long time. please refer attached screenshot for the same Wanted to attach search log as well but can't due to message restriction
Any help or idea over here is very much appreciated, thanks in advance 😊. P.S: Very important thing to notice is if I run any job for any hour manually, I wasn't facing any issues at all 😁.
... View more