Splunk Search

Is it possible to run dashboard panel searches in a staggered sequence instead of all at once?

Ant1D
Motivator

Hey,

I have a dashboard with 6 charts. When I open this dashboard in my browser, Splunk attempts to run all 6 searches at the same time to produce these 6 charts. Is there a way to stagger the running of these searches when the dashboard is opened?
Essentially I would like the first chart to load before the second chart starts to load, I would like the second chart to finish loading before the third chart search is executed and so forth.

Post processing is not the answer because the searches are unrelated (the 6 charts are from 6 different unrelated indexes).

Thanks in advance for your help.

1 Solution

gkanapathy
Splunk Employee
Splunk Employee

Maybe but not exactly. Splunk has limits on the number of concurrent searches that may be run on the search head. This can be set globally, but can also be set by role and as a shared total for everyone in a role. If you reach that limit, then searches will be queued. In practice, this means you can't limit a dashboard specifically to do this. But it does mean you can cause this to happen for specific people for all dashboards.

View solution in original post

arlington
Explorer

Check out this post. There are actually several nice workarounds:

https://answers.splunk.com/answers/511694/i-have-6-panels-on-a-dashboard-but-can-only-run-3.html

0 Karma

moesaidi
Path Finder

I second @AntD
This sounds like a very nice feature to include in an upcoming release of Splunk (ability to stagger panels so they load one at a time, or 3 at a time, etc..)

gkanapathy
Splunk Employee
Splunk Employee

Maybe but not exactly. Splunk has limits on the number of concurrent searches that may be run on the search head. This can be set globally, but can also be set by role and as a shared total for everyone in a role. If you reach that limit, then searches will be queued. In practice, this means you can't limit a dashboard specifically to do this. But it does mean you can cause this to happen for specific people for all dashboards.

Ant1D
Motivator

Hi gkanapathy, thanks for your feedback. I understand although this workaround will be cumbersome to manage. I think this is something for Splunk maybe to implement in a future version of Splunk.

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...