We get the error such as -
[subsearch]: Search auto-finalized after time limit(60 seconds) reached.
We changed the following for the search app while we use a different app -
$ cat limits.conf
[search]
# setting for an hour
maxtime = 216000
Any ideas?
We ended up having the following in limits.conf
-
[subsearch]
maxout = 50000
maxtime = 3600
ttl = 300
[join]
subsearch_maxout = 50000
subsearch_maxtime = 3600
subsearch_timeout = 360
It works!!! ; - )
We ended up having the following in limits.conf
-
[subsearch]
maxout = 50000
maxtime = 3600
ttl = 300
[join]
subsearch_maxout = 50000
subsearch_maxtime = 3600
subsearch_timeout = 360
It works!!! ; - )
You could run a scheduled search to pull the hunk data in on a regular basis and then use loadjob
in your subsearch to access the hunk data from the scheduled search (or ref
if in a dashboard panel).
Interesting - we should try that...
You should show your subsearch; there must be something wrong with it taking so long. It needs optimization.
It's a Hunk one - huge data set ; -)
One of the very few GOOD reasons to resort to upping the timeout.
Very kind @woodcock ; -)
But, you see, why does the error message speak about 60 seconds after we upped the timeout interval to an hour?
did you restart splunk after changing the configuration?
Oh yeah - we did.