<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Searches Delayed_exceeded the yellow thresholds in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-Searches-Delayed-exceeded-the-yellow-thresholds/m-p/596453#M12457</link>
    <description>&lt;P&gt;Yes, facing this issue in Enterprise Security.&lt;/P&gt;</description>
    <pubDate>Thu, 05 May 2022 04:43:48 GMT</pubDate>
    <dc:creator>dhans2022</dc:creator>
    <dc:date>2022-05-05T04:43:48Z</dc:date>
    <item>
      <title>Why is Searches Delayed_exceeded the yellow thresholds?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-Searches-Delayed-exceeded-the-yellow-thresholds/m-p/596383#M12453</link>
      <description>&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;The percentage of non high priority searches delayed (19%) over the last 24 hours is very high and exceeded the yellow thresholds (10%) on this Splunk instance. Total Searches that were part of this percentage=5927. Total delayed Searches=1141&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;Can anyone help me out.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2022 16:36:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-Searches-Delayed-exceeded-the-yellow-thresholds/m-p/596383#M12453</guid>
      <dc:creator>dhans2022</dc:creator>
      <dc:date>2022-05-04T16:36:13Z</dc:date>
    </item>
    <item>
      <title>Re: Searches Delayed_exceeded the yellow thresholds</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-Searches-Delayed-exceeded-the-yellow-thresholds/m-p/596388#M12454</link>
      <description>&lt;P&gt;Take a look at the Monitoring Console to see what searches are being delayed and why. Go to Monitoring Console -&amp;gt; Search -&amp;gt; Scheduler Activity: Instance and take a look at the "Count of Skipped Reports by Name and Reason"&lt;BR /&gt;It could be there are multiple searches running at the same time.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What type of server is having this error? Is it a normal Search Head or is it a Search Head running correlational searches (Ex: Enterprise Security)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2022 13:53:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-Searches-Delayed-exceeded-the-yellow-thresholds/m-p/596388#M12454</guid>
      <dc:creator>Stefanie</dc:creator>
      <dc:date>2022-05-04T13:53:51Z</dc:date>
    </item>
    <item>
      <title>Re: Searches Delayed_exceeded the yellow thresholds</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-Searches-Delayed-exceeded-the-yellow-thresholds/m-p/596453#M12457</link>
      <description>&lt;P&gt;Yes, facing this issue in Enterprise Security.&lt;/P&gt;</description>
      <pubDate>Thu, 05 May 2022 04:43:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-Searches-Delayed-exceeded-the-yellow-thresholds/m-p/596453#M12457</guid>
      <dc:creator>dhans2022</dc:creator>
      <dc:date>2022-05-05T04:43:48Z</dc:date>
    </item>
    <item>
      <title>Re: Searches Delayed_exceeded the yellow thresholds</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-Searches-Delayed-exceeded-the-yellow-thresholds/m-p/597160#M12488</link>
      <description>&lt;P&gt;Since it is affecting Enterprise Security I would assume that you have many correlational searches enabled. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;BR /&gt;Are you familiar with Correlational searches?&lt;BR /&gt;&lt;BR /&gt;It sounds like you may need to disable the searches that are not required for your Use case.&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2022 12:56:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-Searches-Delayed-exceeded-the-yellow-thresholds/m-p/597160#M12488</guid>
      <dc:creator>Stefanie</dc:creator>
      <dc:date>2022-05-10T12:56:26Z</dc:date>
    </item>
  </channel>
</rss>

