<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Health Monitor Engine - Scheduler: Lags and Skipped in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Health-Monitor-Engine-Scheduler-Lags-and-Skipped/m-p/672583#M18177</link>
    <description>&lt;P&gt;Hi there.&lt;BR /&gt;I would like to know about Splunk Health engine, Enterprise 8.2.12, 3 SHC,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="verbal_666_1-1703216686894.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/28649iE3EE1B240720C341/image-size/medium?v=v2&amp;amp;px=400" role="button" title="verbal_666_1-1703216686894.png" alt="verbal_666_1-1703216686894.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;HOW it considers a savedsearch a Lagged search? Based on same previous 24h search runs and doing an average running times? Since we have many many heavy searches that end up also in 10/15m&lt;/LI&gt;&lt;LI&gt;WHY, sometimes, i found in Skipped search monitor a 100% of skipped search (1 from 1, when we have hundreds of scheduled searches)? WHILE, searching the scheduler log, i found something like 70.000 success / 68 skipped (scheduled every minute or every two, concurrency is a factor i calculate and there's no problem) in last 24h ? WHY 100%? Is it a bug? I also search for a single scheduled search per day savedsearches, but all (few) are in "&lt;EM&gt;success&lt;/EM&gt;" status &lt;span class="lia-unicode-emoji" title=":face_with_rolling_eyes:"&gt;🙄&lt;/span&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;When those strange things occur, sometimes, restarting the cluster, make health monitor to reset without warnings!!! Other times, in reverse, restarting the cluster make a clean health monitor to start giving warnings from point 1 &amp;amp; 2 &lt;span class="lia-unicode-emoji" title=":face_with_rolling_eyes:"&gt;🙄&lt;/span&gt; ... strange behaviour!!! &lt;span class="lia-unicode-emoji" title=":unamused_face:"&gt;😒&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Fri, 22 Dec 2023 03:58:46 GMT</pubDate>
    <dc:creator>verbal_666</dc:creator>
    <dc:date>2023-12-22T03:58:46Z</dc:date>
    <item>
      <title>Health Monitor Engine - Scheduler: Lags and Skipped</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Health-Monitor-Engine-Scheduler-Lags-and-Skipped/m-p/672583#M18177</link>
      <description>&lt;P&gt;Hi there.&lt;BR /&gt;I would like to know about Splunk Health engine, Enterprise 8.2.12, 3 SHC,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="verbal_666_1-1703216686894.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/28649iE3EE1B240720C341/image-size/medium?v=v2&amp;amp;px=400" role="button" title="verbal_666_1-1703216686894.png" alt="verbal_666_1-1703216686894.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;HOW it considers a savedsearch a Lagged search? Based on same previous 24h search runs and doing an average running times? Since we have many many heavy searches that end up also in 10/15m&lt;/LI&gt;&lt;LI&gt;WHY, sometimes, i found in Skipped search monitor a 100% of skipped search (1 from 1, when we have hundreds of scheduled searches)? WHILE, searching the scheduler log, i found something like 70.000 success / 68 skipped (scheduled every minute or every two, concurrency is a factor i calculate and there's no problem) in last 24h ? WHY 100%? Is it a bug? I also search for a single scheduled search per day savedsearches, but all (few) are in "&lt;EM&gt;success&lt;/EM&gt;" status &lt;span class="lia-unicode-emoji" title=":face_with_rolling_eyes:"&gt;🙄&lt;/span&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;When those strange things occur, sometimes, restarting the cluster, make health monitor to reset without warnings!!! Other times, in reverse, restarting the cluster make a clean health monitor to start giving warnings from point 1 &amp;amp; 2 &lt;span class="lia-unicode-emoji" title=":face_with_rolling_eyes:"&gt;🙄&lt;/span&gt; ... strange behaviour!!! &lt;span class="lia-unicode-emoji" title=":unamused_face:"&gt;😒&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Dec 2023 03:58:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Health-Monitor-Engine-Scheduler-Lags-and-Skipped/m-p/672583#M18177</guid>
      <dc:creator>verbal_666</dc:creator>
      <dc:date>2023-12-22T03:58:46Z</dc:date>
    </item>
    <item>
      <title>Re: Health Monitor Engine - Scheduler: Lags and Skipped</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Health-Monitor-Engine-Scheduler-Lags-and-Skipped/m-p/673359#M18268</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;this could explain that behaviour to you&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.1.2/DMC/Configurefeaturemonitoring" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.1.2/DMC/Configurefeaturemonitoring&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Based on this instructions you could see what those health messages means.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jan 2024 13:59:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Health-Monitor-Engine-Scheduler-Lags-and-Skipped/m-p/673359#M18268</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2024-01-05T13:59:45Z</dc:date>
    </item>
  </channel>
</rss>

