<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Enteprise Delayed searches in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Enteprise-Delayed-searches/m-p/757062#M120091</link>
    <description>&lt;P&gt;Searches are delayed because too many searches are trying to run at the same time.&amp;nbsp; There are a few things you can do about it.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Ensure all instances meet or exceed Splunk's Reference Hardware specification.&lt;/LI&gt;&lt;LI&gt;Ensure Splunk Enterprise Security runs on a dedicated Search Head (or SHC).&amp;nbsp; Do not run searches unrelated to ES on that SH.&lt;/LI&gt;&lt;LI&gt;Eliminate unneeded scheduled searches.&lt;/LI&gt;&lt;LI&gt;Prohibit real-time searches.&lt;/LI&gt;&lt;LI&gt;Verify all scheduled searches complete as quickly as possible.&amp;nbsp; Do this by minimizing their search windows and using efficient searches.&lt;/LI&gt;&lt;LI&gt;Implement Allow Skew and Schedule Windows.&lt;/LI&gt;&lt;LI&gt;Distribute search run times evenly across the clock.&amp;nbsp; Avoid running at peak times such as 0, 15, 30, or 45 minutes of each hour.&lt;/LI&gt;&lt;LI&gt;Consider using Workload Management to control the search behavior of users.&lt;/LI&gt;&lt;LI&gt;Move daily/weekly/monthly scheduled searches to off hours.&lt;/LI&gt;&lt;/OL&gt;</description>
    <pubDate>Tue, 13 Jan 2026 12:52:05 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2026-01-13T12:52:05Z</dc:date>
    <item>
      <title>Splunk Enteprise Delayed searches</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Enteprise-Delayed-searches/m-p/757061#M120090</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;&lt;P&gt;I wanna ask something that I really cannot figure out by myself , I have a splunk entreprise Installed on an&amp;nbsp; ubuntu with over 2 To , 32 Go of RAM and 38 CPU.&amp;nbsp;&lt;/P&gt;&lt;P&gt;With all these I still get so many delayed searches (up to 97%) :&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;""The percentage of non high priority searches delayed (99%) over the last 24 hours is very high and exceeded the red thresholds (20%) on this Splunk instance.""&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I really do not know the reason , is it because we are using ES Security or what exactly.&lt;/P&gt;&lt;P&gt;Thank you for your time.&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jan 2026 11:39:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Enteprise-Delayed-searches/m-p/757061#M120090</guid>
      <dc:creator>fedayn05</dc:creator>
      <dc:date>2026-01-08T11:39:07Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enteprise Delayed searches</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Enteprise-Delayed-searches/m-p/757062#M120091</link>
      <description>&lt;P&gt;Searches are delayed because too many searches are trying to run at the same time.&amp;nbsp; There are a few things you can do about it.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Ensure all instances meet or exceed Splunk's Reference Hardware specification.&lt;/LI&gt;&lt;LI&gt;Ensure Splunk Enterprise Security runs on a dedicated Search Head (or SHC).&amp;nbsp; Do not run searches unrelated to ES on that SH.&lt;/LI&gt;&lt;LI&gt;Eliminate unneeded scheduled searches.&lt;/LI&gt;&lt;LI&gt;Prohibit real-time searches.&lt;/LI&gt;&lt;LI&gt;Verify all scheduled searches complete as quickly as possible.&amp;nbsp; Do this by minimizing their search windows and using efficient searches.&lt;/LI&gt;&lt;LI&gt;Implement Allow Skew and Schedule Windows.&lt;/LI&gt;&lt;LI&gt;Distribute search run times evenly across the clock.&amp;nbsp; Avoid running at peak times such as 0, 15, 30, or 45 minutes of each hour.&lt;/LI&gt;&lt;LI&gt;Consider using Workload Management to control the search behavior of users.&lt;/LI&gt;&lt;LI&gt;Move daily/weekly/monthly scheduled searches to off hours.&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Tue, 13 Jan 2026 12:52:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Enteprise-Delayed-searches/m-p/757062#M120091</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2026-01-13T12:52:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enteprise Delayed searches</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Enteprise-Delayed-searches/m-p/757064#M120092</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/313418"&gt;@fedayn05&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;in addition to the checks hinted by&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;check the IOPS of your storage (e.g. using Bonnie++ or anothe tool) : probably this is the bottleneck.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jan 2026 13:59:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Enteprise-Delayed-searches/m-p/757064#M120092</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2026-01-08T13:59:06Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enteprise Delayed searches</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Enteprise-Delayed-searches/m-p/757144#M120107</link>
      <description>Please, tell more about your architecture, deployment, splunk version, daily ingestion amount also how many searches (scheduled vs ad-hoc) you have.</description>
      <pubDate>Fri, 09 Jan 2026 21:28:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Enteprise-Delayed-searches/m-p/757144#M120107</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2026-01-09T21:28:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enteprise Delayed searches</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Enteprise-Delayed-searches/m-p/757214#M120115</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Thank you for your time.&amp;nbsp; I am using a single ubuntu 22.04 instance for Splunk&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;ubuntu with over 2 To , 32 Go of RAM and 38 CPU.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I am using the 10.0.0 version , about the daily ingestion it is around 40 Go.&lt;/P&gt;&lt;P&gt;As i am new to splunk i did not get what you meant by&amp;nbsp;&lt;SPAN&gt;searches (scheduled vs ad-hoc)&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jan 2026 11:32:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Enteprise-Delayed-searches/m-p/757214#M120115</guid>
      <dc:creator>fedayn05</dc:creator>
      <dc:date>2026-01-13T11:32:22Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enteprise Delayed searches</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Enteprise-Delayed-searches/m-p/757215#M120116</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Thank you for your time. I have checked this first and it was actually not the source of the problem.&lt;/P&gt;&lt;P&gt;Thank you for your time.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jan 2026 11:33:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Enteprise-Delayed-searches/m-p/757215#M120116</guid>
      <dc:creator>fedayn05</dc:creator>
      <dc:date>2026-01-13T11:33:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enteprise Delayed searches</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Enteprise-Delayed-searches/m-p/757216#M120117</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Thank you for your time.&lt;/P&gt;&lt;P&gt;As I am a bit new to splunk , I would appreciate it if you can please explain a bit further these steps.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jan 2026 11:35:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Enteprise-Delayed-searches/m-p/757216#M120117</guid>
      <dc:creator>fedayn05</dc:creator>
      <dc:date>2026-01-13T11:35:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enteprise Delayed searches</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Enteprise-Delayed-searches/m-p/757219#M120119</link>
      <description>&lt;P&gt;They are not "steps".&amp;nbsp; They're separate checks/measures to perform to try to alleviate delayed searches.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;See&amp;nbsp;&lt;A href="https://help.splunk.com/en/splunk-enterprise/get-started/deployment-capacity-manual/9.4/performance-reference/reference-hardware" target="_blank"&gt;https://help.splunk.com/en/splunk-enterprise/get-started/deployment-capacity-manual/9.4/performance-reference/reference-hardware&lt;/A&gt;&amp;nbsp;and&amp;nbsp;&lt;A href="https://help.splunk.com/en/splunk-enterprise-security-8/install/8.1/planning/minimum-specifications-for-a-production-deployment" target="_blank"&gt;https://help.splunk.com/en/splunk-enterprise-security-8/install/8.1/planning/minimum-specifications-for-a-production-deployment&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;Enterprise Security is a very resource-intensive application.&amp;nbsp; Therefore, it is recommended to install ES on a separate Splunk instance.&amp;nbsp; It can, however, share indexers with other search heads.&lt;/LI&gt;&lt;LI&gt;This should require no explanation.&lt;/LI&gt;&lt;LI&gt;Real-time searches pin themselves to a CPU, preventing other searches from running there.&amp;nbsp; Don't use real-time searches.&amp;nbsp; See&amp;nbsp;&lt;A href="https://help.splunk.com/en/splunk-cloud-platform/search/search-manual/9.2.2406/search-and-report-in-real-time/about-real-time-searches-and-reports" target="_blank"&gt;https://help.splunk.com/en/splunk-cloud-platform/search/search-manual/9.2.2406/search-and-report-in-real-time/about-real-time-searches-and-reports&lt;/A&gt;&amp;nbsp;for more.&lt;/LI&gt;&lt;LI&gt;Entire books could be written on making searches more efficient.&amp;nbsp; Splunk has one at&amp;nbsp;&lt;A href="https://help.splunk.com/en/splunk-enterprise/search/search-manual/9.4/optimizing-searches/about-search-optimization" target="_blank"&gt;https://help.splunk.com/en/splunk-enterprise/search/search-manual/9.4/optimizing-searches/about-search-optimization&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;Allow Skew gives the search scheduler permission to adjust the run time of a scheduled search to one with fewer other searches scheduled.&amp;nbsp; Search Windows allow the scheduler to delay the start of a scheduled search in the event that resources are not yet available.&amp;nbsp; See&amp;nbsp;&lt;A href="https://help.splunk.com/en/splunk-enterprise/create-dashboards-and-reports/reporting-manual/10.0/report-management/offset-scheduled-search-start-times" target="_blank"&gt;https://help.splunk.com/en/splunk-enterprise/create-dashboards-and-reports/reporting-manual/10.0/report-management/offset-scheduled-search-start-times&lt;/A&gt;&amp;nbsp;and&amp;nbsp;&lt;A href="https://www.splunk.com/en_us/blog/platform/schedule-windows-vs-skewing.html" target="_blank"&gt;https://www.splunk.com/en_us/blog/platform/schedule-windows-vs-skewing.html&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;There is a strong tendency among Splunk users to run their scheduled searches at the top of an hour.&amp;nbsp; At most of the customers I've visited, this accounts for about half of all scheduled searches and is a source of most of their delayed and skipped searches.&amp;nbsp; It also doesn't account for the 30-90 seconds of delay between when an event is generated and when it is searchable by Splunk.&amp;nbsp; It's far better to use a cron schedule to have the search run at 2-3 minutes after the hour.&amp;nbsp; Other peak search periods to avoid are 15, 30, and 45 minutes into any hour of the day.&lt;/LI&gt;&lt;LI&gt;Splunk's Workload Management feature gives Splunk admins some control over how resource contention (CPU and memory) is handled.&amp;nbsp; It also can be used to stop long-running searches, prevent real-time searches, and prevent users from running searches during peak times.&amp;nbsp; See&amp;nbsp;&lt;A href="https://help.splunk.com/en/splunk-enterprise/administer/manage-workloads/9.4/workload-management-overview/about-workload-management" target="_blank"&gt;https://help.splunk.com/en/splunk-enterprise/administer/manage-workloads/9.4/workload-management-overview/about-workload-management &lt;/A&gt;for details.&lt;/LI&gt;&lt;LI&gt;I've seen plenty of instances where a reports run once a day or even every week at 8 or 9 in the morning.&amp;nbsp; This usually is unnecessary and takes away "slots" from other searches.&amp;nbsp; Instead, these types of "batch" reports should run in less busy times of day such as 3am or on weekends.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jan 2026 13:27:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Enteprise-Delayed-searches/m-p/757219#M120119</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2026-01-13T13:27:14Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enteprise Delayed searches</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Enteprise-Delayed-searches/m-p/757232#M120122</link>
      <description>&lt;P&gt;I missed ES part earlier. It probably explains your issues. It depends on how many correlation searches and CIM accelerations are running your single box, but I suspect that your environment is too much for running it in single node.&lt;/P&gt;&lt;P&gt;You could find monitoring console under settings. There are links/icon for it. Just click it and then enable it from its setting tab/link. After that there are Search link where you could look those several dashboards which shows e.g. what are those deferred and skipped searches.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jan 2026 18:09:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Enteprise-Delayed-searches/m-p/757232#M120122</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2026-01-13T18:09:19Z</dc:date>
    </item>
  </channel>
</rss>

