Getting Data In

Different search performance for two sourcetype

pradeepchhetri
Engager

Hi,

We have a splunk machine running with all the events going to one index. I noticed that for two different sourcetype, I got different search performance. For one of the sourcetype, searching happened very quickly but it was very slow for the other. Can someone explain me why i am getting such a difference.

Regards.

Tags (2)
0 Karma
1 Solution

MuS
Legend

Hi pradeepchhetri,

This is the kind of question, that is almost impossible for anyone to answer, except to you - because you know your setup, know your events, know your server's load and so on.....

here are some basic troubleshooting things:

  • do both sourcetypes have exactly the same event count over the exact same time range?
  • is your search head / indexer over loaded?
  • are there any saved searches running?
  • check the job inspector to get any idea why one search is running slower as the other.

you see, there is a lot to check for you.

cheers, MuS

View solution in original post

MuS
Legend

Hi pradeepchhetri,

This is the kind of question, that is almost impossible for anyone to answer, except to you - because you know your setup, know your events, know your server's load and so on.....

here are some basic troubleshooting things:

  • do both sourcetypes have exactly the same event count over the exact same time range?
  • is your search head / indexer over loaded?
  • are there any saved searches running?
  • check the job inspector to get any idea why one search is running slower as the other.

you see, there is a lot to check for you.

cheers, MuS

pradeepchhetri
Engager

@Mus: @martin_mueller: Just realized that the difference was due to fast-mode and smart-mode search types, although both has same number of events. Thank you for the help.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

I'm going to guess that production will have much more data than staging.

0 Karma

pradeepchhetri
Engager

@Mus: Thank you for the reply. I will do the troubleshooting accordingly and let you know the outcome.

0 Karma

pradeepchhetri
Engager

my search query just includes: sourcetype="production" and sourcetype="staging"

0 Karma

splunker12er
Motivator

Can you post your search query ?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...