Splunk Search

auto-finalized after time limit ( 30 seconds )

abhayneilam
Contributor

I am getting the following warning while running my big query :

auto-finalized after time limit ( 30 seconds ) reached

can you please let me know what to do if I get this warning, and how does it effect to my query result.and how to increase the time limit for this

0 Karma

marellasunil
Communicator

Or you can use
... |append maxtime=100 [search ... ]

0 Karma

marellasunil
Communicator

The query will finalize its search and you will receive the result till 30 secs only (Not actual result).
If you are having any sub searches, change the time limit in limits.conf (Splunk\etc\system\default\limits.conf).
Hopefully it will work...

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...