<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Searches Skipped in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Searches-Skipped/m-p/574283#M10647</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp; After identifying those searches, what is the process to remove the warning message, since we are seeing the similar kind of issue on our SH where our SH health is red.&lt;/P&gt;&lt;P&gt;Does a SH cluster restart help?&lt;/P&gt;</description>
    <pubDate>Tue, 09 Nov 2021 20:22:04 GMT</pubDate>
    <dc:creator>Roy_9</dc:creator>
    <dc:date>2021-11-09T20:22:04Z</dc:date>
    <item>
      <title>Splunk Searches Skipped</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Searches-Skipped/m-p/574270#M10645</link>
      <description>&lt;P&gt;Splunk Searches Skipped on the Cluster master console error messages&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;The percentage of non high priority searches skipped (44%) over the last 24 hours is very high and exceeded the red thresholds (20%) on this Splunk instance. Total Searches that were part of this percentage=1608..... Total skipped Searches=720...&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Tue, 09 Nov 2021 18:26:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Searches-Skipped/m-p/574270#M10645</guid>
      <dc:creator>rlsplunker</dc:creator>
      <dc:date>2021-11-09T18:26:07Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Searches Skipped</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Searches-Skipped/m-p/574274#M10646</link>
      <description>&lt;P&gt;You should check what those are from MC (Settings - Monitoring Console - Searches - Schedule searches). There you can see when, where and what those are.&amp;nbsp;&lt;BR /&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Tue, 09 Nov 2021 18:47:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Searches-Skipped/m-p/574274#M10646</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-11-09T18:47:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Searches Skipped</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Searches-Skipped/m-p/574283#M10647</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp; After identifying those searches, what is the process to remove the warning message, since we are seeing the similar kind of issue on our SH where our SH health is red.&lt;/P&gt;&lt;P&gt;Does a SH cluster restart help?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Nov 2021 20:22:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Searches-Skipped/m-p/574283#M10647</guid>
      <dc:creator>Roy_9</dc:creator>
      <dc:date>2021-11-09T20:22:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Searches Skipped</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Searches-Skipped/m-p/574348#M10652</link>
      <description>&lt;P&gt;After you have identified those, you also see what was the reason for that. Then just fix the reason one by one. That could be e.g. too many search at same time =&amp;gt; reschedule, no permission to indexed/run =&amp;gt; fix permission/change ownership etc.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Nov 2021 08:55:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Searches-Skipped/m-p/574348#M10652</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-11-10T08:55:54Z</dc:date>
    </item>
  </channel>
</rss>

