<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Scheduled searches getting skipped due to rolling restart in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-are-scheduled-searches-getting-skipped-due-to-rolling/m-p/642260#M16245</link>
    <description>&lt;P&gt;Master should _not_ initiate restart out of thin air. There must be something that triggers it.&lt;/P&gt;&lt;P&gt;Also see &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Indexer/Userollingrestart#How_searchable_rolling_restart_works" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Indexer/Userollingrestart#How_searchable_rolling_restart_works&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The timeouts and wait times can impact whether your searches get skipped.&lt;/P&gt;</description>
    <pubDate>Thu, 04 May 2023 10:03:37 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2023-05-04T10:03:37Z</dc:date>
    <item>
      <title>Why are scheduled searches getting skipped due to rolling restart?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-are-scheduled-searches-getting-skipped-due-to-rolling/m-p/642238#M16240</link>
      <description>&lt;P&gt;We have an issue where all the scheduled searches are getting skipped whenever rolling restart is in progress.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, since few weeks, we have observed that the cluster master automatically initiates a rolling restart of the indexers, twice in a week. It takes about 24 hours to restart all the 24 indexers in a cluster, which impacts our business too.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone ever incurred this situation before?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2023 12:48:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-are-scheduled-searches-getting-skipped-due-to-rolling/m-p/642238#M16240</guid>
      <dc:creator>shadysplunker</dc:creator>
      <dc:date>2023-05-04T12:48:28Z</dc:date>
    </item>
    <item>
      <title>Re: Scheduled searches getting skipped due to rolling restart</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-are-scheduled-searches-getting-skipped-due-to-rolling/m-p/642260#M16245</link>
      <description>&lt;P&gt;Master should _not_ initiate restart out of thin air. There must be something that triggers it.&lt;/P&gt;&lt;P&gt;Also see &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Indexer/Userollingrestart#How_searchable_rolling_restart_works" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Indexer/Userollingrestart#How_searchable_rolling_restart_works&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The timeouts and wait times can impact whether your searches get skipped.&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2023 10:03:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-are-scheduled-searches-getting-skipped-due-to-rolling/m-p/642260#M16245</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-05-04T10:03:37Z</dc:date>
    </item>
    <item>
      <title>Re: Scheduled searches getting skipped due to rolling restart</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-are-scheduled-searches-getting-skipped-due-to-rolling/m-p/642267#M16246</link>
      <description>&lt;P&gt;Thanks for pointing me out to a proper direction!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's our config from [clustering] stanza:&lt;/P&gt;&lt;P&gt;[clustering]&lt;BR /&gt;mode = master&lt;BR /&gt;multisite = true&lt;BR /&gt;available_sites = site1, site2&lt;BR /&gt;site_replication_factor = origin:1, site1:1, site2:1, total:3&lt;BR /&gt;site_search_factor = origin:1, site1:1, site2:1, total:2&lt;BR /&gt;cluster_label = cluster1&lt;BR /&gt;maintenance_mode = false&lt;BR /&gt;max_peers_to_download_bundle = 10&lt;BR /&gt;service_interval = 10&lt;BR /&gt;heartbeat_timeout = 1800&lt;BR /&gt;cxn_timeout = 300&lt;BR /&gt;send_timeout = 300&lt;BR /&gt;rcv_timeout = 300&lt;BR /&gt;max_peer_build_load = 5&lt;BR /&gt;rolling_restart = searchable&lt;BR /&gt;restart_timeout = 500&lt;BR /&gt;decommission_force_timeout = 900&lt;BR /&gt;restart_inactivity_timeout = 1500&lt;BR /&gt;rebalance_threshold = 0.96&lt;BR /&gt;max_auto_service_interval = 250&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I suspect few things here like "rolling_restart" should be "searchble_force" and max_peers_to_download_bundle would be more than 10? considering we have 24 indexers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will go through all these parameters and understand it in detail.&lt;/P&gt;&lt;P&gt;Do you suspect anything unusual in the configuration here? It would be much helpful! Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2023 10:24:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-are-scheduled-searches-getting-skipped-due-to-rolling/m-p/642267#M16246</guid>
      <dc:creator>shadysplunker</dc:creator>
      <dc:date>2023-05-04T10:24:21Z</dc:date>
    </item>
  </channel>
</rss>

