<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Health:Red in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Health-Red/m-p/510496#M4369</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I think that correct item is "Scheduler Activity: Instance". If I recall right it is under the Search Head item on distributed environment?&lt;/P&gt;</description>
    <pubDate>Wed, 22 Jul 2020 17:02:52 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2020-07-22T17:02:52Z</dc:date>
    <item>
      <title>Health:Red</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Health-Red/m-p/509935#M4341</link>
      <description>&lt;P&gt;I cannot find what is doing this and the answer that google always brings back from the community is not very good.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Root Cause(s):&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;The number of extremely lagged searches (1) over the last hour exceeded the red threshold (1) on this Splunk instance&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Mon, 20 Jul 2020 01:03:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Health-Red/m-p/509935#M4341</guid>
      <dc:creator>kmill78</dc:creator>
      <dc:date>2020-07-20T01:03:01Z</dc:date>
    </item>
    <item>
      <title>Re: Health:Red</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Health-Red/m-p/509950#M4342</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;use the MC (monitoring console) to check what is status of scheduled searches. It should show to you which search and why is caused this warning.&amp;nbsp;&lt;BR /&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 04:48:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Health-Red/m-p/509950#M4342</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-07-20T04:48:17Z</dc:date>
    </item>
    <item>
      <title>Re: Health:Red</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Health-Red/m-p/510313#M4362</link>
      <description>&lt;P&gt;hey thanks ! would you know where exactly in the MC ?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 00:12:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Health-Red/m-p/510313#M4362</guid>
      <dc:creator>kmill78</dc:creator>
      <dc:date>2020-07-22T00:12:36Z</dc:date>
    </item>
    <item>
      <title>Re: Health:Red</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Health-Red/m-p/510321#M4363</link>
      <description>&lt;P&gt;depending on your environment, the monitoring console will be available at Settings &amp;gt; Monitoring Console&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.5/DMC/DMCoverview" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.5/DMC/DMCoverview&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I believe search lag is a symptom of skipped or differed searches...check out the search related stats and review your server resources&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 01:30:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Health-Red/m-p/510321#M4363</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2020-07-22T01:30:44Z</dc:date>
    </item>
    <item>
      <title>Re: Health:Red</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Health-Red/m-p/510417#M4365</link>
      <description>&lt;P&gt;thank you very much ! i know how to get in to th MC , its from there i get lost &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 12:33:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Health-Red/m-p/510417#M4365</guid>
      <dc:creator>kmill78</dc:creator>
      <dc:date>2020-07-22T12:33:43Z</dc:date>
    </item>
    <item>
      <title>Re: Health:Red</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Health-Red/m-p/510458#M4368</link>
      <description>&lt;P&gt;dont worry ill tie this rope to your waist....dive in, you wont get lost...docs has a guide for how to interpret the data (see link i posted above). Once you have touched the bottom of the pool come back up for some air and let us know what you working with and what you have tried!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mattymo_0-1595426983921.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9822i78EAE4C33DBD1EFD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="mattymo_0-1595426983921.png" alt="mattymo_0-1595426983921.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Otherwise, check your jobs tab in splunk and look for jobs that are queued or differed. Also it says 1 search, can you not click into it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mattymo_0-1595427206401.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9823i18AABC25DB413D08/image-size/medium?v=v2&amp;amp;px=400" role="button" title="mattymo_0-1595427206401.png" alt="mattymo_0-1595427206401.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 14:13:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Health-Red/m-p/510458#M4368</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2020-07-22T14:13:34Z</dc:date>
    </item>
    <item>
      <title>Re: Health:Red</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Health-Red/m-p/510496#M4369</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I think that correct item is "Scheduler Activity: Instance". If I recall right it is under the Search Head item on distributed environment?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 17:02:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Health-Red/m-p/510496#M4369</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-07-22T17:02:52Z</dc:date>
    </item>
  </channel>
</rss>

