Splunk Search

What happens to an incomplete search run on one dashboard, but the user changes to another dashboard?

Lucas_K
Motivator

What happens when a search that is kicked off by a dashboard but is then abandoned by the user? ie. they change to another dashboard etc? How does this interact with a distributed environment?

Does the splunkweb process realise that there is no web interface to send the results back to and sends the search peers a signal to stop the searches or do they continue to run until complete? If so it seems like there is plenty of potential for wasted resources.

1 Solution

gkanapathy
Splunk Employee
Splunk Employee

Unless a search is explicitly sent to the background, it is killed when the UI page that dispatched it is no longer connecting to SplunkWeb and Splunkd. Backgrounded searches continue to run, as that is the point of sending a search to the background.

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

Unless a search is explicitly sent to the background, it is killed when the UI page that dispatched it is no longer connecting to SplunkWeb and Splunkd. Backgrounded searches continue to run, as that is the point of sending a search to the background.

Lucas_K
Motivator

Thanks. You were the exact person I was hoping would answer. It was something i'd always wondered and figured I'd be able to probably tell from internal logs but thought i'd just ask 🙂

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...