<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk ES on SHC  notable issue in Other Admin</title>
    <link>https://community.splunk.com/t5/Other-Admin/Splunk-ES-on-SHC-notable-issue/m-p/631851#M48</link>
    <description>&lt;P&gt;Hi Folks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a SHC 3 members&amp;nbsp; with splunk ES, currently when the ES trigger a notable, the notable trigger 3 times the throttling is correctly configured.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;By my opinion the SHC out of sync do you have any suggestions?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Wed, 22 Feb 2023 14:07:31 GMT</pubDate>
    <dc:creator>aasabatini</dc:creator>
    <dc:date>2023-02-22T14:07:31Z</dc:date>
    <item>
      <title>Splunk ES on SHC  notable issue</title>
      <link>https://community.splunk.com/t5/Other-Admin/Splunk-ES-on-SHC-notable-issue/m-p/631851#M48</link>
      <description>&lt;P&gt;Hi Folks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a SHC 3 members&amp;nbsp; with splunk ES, currently when the ES trigger a notable, the notable trigger 3 times the throttling is correctly configured.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;By my opinion the SHC out of sync do you have any suggestions?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 22 Feb 2023 14:07:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Admin/Splunk-ES-on-SHC-notable-issue/m-p/631851#M48</guid>
      <dc:creator>aasabatini</dc:creator>
      <dc:date>2023-02-22T14:07:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES on SHC  notable issue</title>
      <link>https://community.splunk.com/t5/Other-Admin/Splunk-ES-on-SHC-notable-issue/m-p/703358#M49</link>
      <description>&lt;P&gt;Did you find solution to this?&lt;/P&gt;&lt;P&gt;my problem is that it will trigger on all shc members and when i assign notable from on sh it is not reflected on other shs&lt;/P&gt;</description>
      <pubDate>Fri, 01 Nov 2024 22:26:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Admin/Splunk-ES-on-SHC-notable-issue/m-p/703358#M49</guid>
      <dc:creator>Nawab</dc:creator>
      <dc:date>2024-11-01T22:26:14Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES on SHC  notable issue</title>
      <link>https://community.splunk.com/t5/Other-Admin/Splunk-ES-on-SHC-notable-issue/m-p/703371#M50</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244855"&gt;@Nawab&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;the correct action is that the Correlation Search is runned on only one of the SHs and only one Notable is created.&lt;/P&gt;&lt;P&gt;If more than one Notable is created, means that the Cluster is out of sync, as&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222210"&gt;@aasabatini&lt;/a&gt;&amp;nbsp;said.&lt;/P&gt;&lt;P&gt;In this case, you have to check the sync and restart the members and eventually rebuild the configurations.&lt;/P&gt;&lt;P&gt;For more infos see at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.3.1/DistSearch/SHCdeploymentoverview" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.3.1/DistSearch/SHCdeploymentoverview&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sat, 02 Nov 2024 07:34:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Admin/Splunk-ES-on-SHC-notable-issue/m-p/703371#M50</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-11-02T07:34:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES on SHC  notable issue</title>
      <link>https://community.splunk.com/t5/Other-Admin/Splunk-ES-on-SHC-notable-issue/m-p/703372#M51</link>
      <description>&lt;P&gt;Yes. It does look as if the SHC members weren't properly communicating with one another. What is interesting though is that the captain is responsible for scheduling searches. So if you had connectivity problems you should also have problems with captain election. But your behaviour suggests that each cluster node works independently,&lt;/P&gt;&lt;P&gt;What does your "splunk show shcluster status" say on each node?&lt;/P&gt;</description>
      <pubDate>Sat, 02 Nov 2024 10:04:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Admin/Splunk-ES-on-SHC-notable-issue/m-p/703372#M51</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-11-02T10:04:58Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES on SHC  notable issue</title>
      <link>https://community.splunk.com/t5/Other-Admin/Splunk-ES-on-SHC-notable-issue/m-p/703426#M52</link>
      <description>&lt;P&gt;shcluster status is up.&lt;BR /&gt;&lt;BR /&gt;If notable should trigger on only on and correlation searches only run on 1 search head, what is the point of having a shcluster.&lt;BR /&gt;&lt;BR /&gt;Also what will happen of reports that use notable data.&lt;BR /&gt;How will I control searches to be run on only 1 sh.&lt;/P&gt;</description>
      <pubDate>Sun, 03 Nov 2024 07:24:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Admin/Splunk-ES-on-SHC-notable-issue/m-p/703426#M52</guid>
      <dc:creator>Nawab</dc:creator>
      <dc:date>2024-11-03T07:24:07Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES on SHC  notable issue</title>
      <link>https://community.splunk.com/t5/Other-Admin/Splunk-ES-on-SHC-notable-issue/m-p/703427#M53</link>
      <description>&lt;P&gt;In shcluster the scheduler distributes scheduled searches among shcluster members so that if you have 3 SHs 32 CPUs each, you have effectively 96 CPUs to distribute searches among.&lt;/P&gt;&lt;P&gt;But a single search is run on a single SH and its results are replicated to other members.&lt;/P&gt;&lt;P&gt;Also show shcluster-status shows way more information than just "up".&lt;/P&gt;</description>
      <pubDate>Sun, 03 Nov 2024 07:34:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Admin/Splunk-ES-on-SHC-notable-issue/m-p/703427#M53</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-11-03T07:34:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES on SHC  notable issue</title>
      <link>https://community.splunk.com/t5/Other-Admin/Splunk-ES-on-SHC-notable-issue/m-p/703432#M54</link>
      <description>&lt;P&gt;So now the issue is, Some alarms triggered in 1 sh and others trigger in 2nd sh&lt;/P&gt;</description>
      <pubDate>Sun, 03 Nov 2024 12:26:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Admin/Splunk-ES-on-SHC-notable-issue/m-p/703432#M54</guid>
      <dc:creator>Nawab</dc:creator>
      <dc:date>2024-11-03T12:26:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES on SHC  notable issue</title>
      <link>https://community.splunk.com/t5/Other-Admin/Splunk-ES-on-SHC-notable-issue/m-p/703443#M55</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244855"&gt;@Nawab&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;it's normal: alert runs are distributed between the three Search Heads.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sun, 03 Nov 2024 15:42:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Admin/Splunk-ES-on-SHC-notable-issue/m-p/703443#M55</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-11-03T15:42:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES on SHC  notable issue</title>
      <link>https://community.splunk.com/t5/Other-Admin/Splunk-ES-on-SHC-notable-issue/m-p/704804#M71</link>
      <description>&lt;P&gt;I have solved this issue.&lt;BR /&gt;&lt;BR /&gt;to get the notables accross SHC, you need to send notable data to an index in indexer cluster&lt;/P&gt;&lt;P&gt;using outputs.conf&lt;/P&gt;&lt;P&gt;once data is sent, new notables will be available in all SHs&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2024 11:16:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Admin/Splunk-ES-on-SHC-notable-issue/m-p/704804#M71</guid>
      <dc:creator>Nawab</dc:creator>
      <dc:date>2024-11-20T11:16:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES on SHC  notable issue</title>
      <link>https://community.splunk.com/t5/Other-Admin/Splunk-ES-on-SHC-notable-issue/m-p/704835#M72</link>
      <description>&lt;P&gt;In a well-deployed environment you should _not_ index anything locally except for the indexing tier. (and except for DS-es in the recent versions). You should send all your events to the indexer tier.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2024 14:30:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Admin/Splunk-ES-on-SHC-notable-issue/m-p/704835#M72</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-11-20T14:30:27Z</dc:date>
    </item>
  </channel>
</rss>

