Hello Splunkers
The actual time in job inspector seems to not be very long
But usually there is long latency and job inspector logs are stuck at this point..
INFO DispatchThread - Generating results preview took....
11-17-2017 11:32:26.928 INFO LocalCollector - Final required fields list = _bkt,_cd,_si,_subsecond,host,index,linecount,source,sourcetype,splunk_server
11-17-2017 11:32:26.928 INFO UserManager - Unwound user context: bondo -> NULL
11-17-2017 11:32:26.928 INFO UserManager - Setting user context: bondo
11-17-2017 11:32:26.928 INFO UserManager - Done setting user context: NULL -> bondo
11-17-2017 11:32:26.928 INFO UserManager - Unwound user context: bondo -> NULL
11-17-2017 11:32:37.438 INFO DispatchThread - Generating results preview took 1 ms
11-17-2017 11:32:47.441 INFO DispatchThread - Generating results preview took 1 ms
11-17-2017 11:32:57.444 INFO DispatchThread - Generating results preview took 1 ms
Are there any tshoot steps for this , perhaps dispatch directory issue etc?
Hi stanwin,
see in Monitoring Console what's the situation of your Search Heads and Indexers, maybe there's some sofference in executing jobs!
Is your HW infrastructure sufficient for the usual load (Indexing an searching)?
Bye.
Giuseppe
THanks Cusello for the response!
I was looking for perhaps direct root causes/tshoot areas if any for that specific point/flow in particular.