<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Searches delayed in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Searches-delayed/m-p/564199#M10217</link>
    <description>&lt;P&gt;Also, make sure to check your firewall settings.&lt;/P&gt;</description>
    <pubDate>Sat, 21 Aug 2021 19:09:06 GMT</pubDate>
    <dc:creator>jvarner</dc:creator>
    <dc:date>2021-08-21T19:09:06Z</dc:date>
    <item>
      <title>Splunk Searches delayed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Searches-delayed/m-p/466690#M6979</link>
      <description>&lt;P&gt;Hi All, &lt;BR /&gt;
I would like to ask why do we encounter this notification:&lt;BR /&gt;
&lt;STRONG&gt;Root Cause(s):&lt;/STRONG&gt;&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;The percentage of high priority searches delayed (16%) over the last 24 hours is very high and exceeded the red thresholds (10%) on this Splunk instance. Total Searches that were part of this percentage=12. Total delayed Searches=2&lt;/LI&gt;
&lt;LI&gt;The percentage of non high priority searches delayed (47%) over the last 24 hours is very high and exceeded the red thresholds (20%) on this Splunk instance. Total Searches that were part of this percentage=21. Total delayed Searches=10&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;May i know what are the possible issue and resolution regarding this?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2019 12:58:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Searches-delayed/m-p/466690#M6979</guid>
      <dc:creator>jadengoho</dc:creator>
      <dc:date>2019-12-17T12:58:09Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Searches delayed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Searches-delayed/m-p/466691#M6980</link>
      <description>&lt;P&gt;I answered a similar question generally here - &lt;A href="https://answers.splunk.com/answers/786499/the-percentage-of-non-high-priority-searches-lagge.html#answer-787630"&gt;https://answers.splunk.com/answers/786499/the-percentage-of-non-high-priority-searches-lagge.html#answer-787630&lt;/A&gt;. The gist is that you can use the Monitoring Console (and it's inherent queries) to better diagnose specifically what your issues are. &lt;/P&gt;

&lt;P&gt;Here's the path (assuming you're a Splunk admin on your instance): Settings (Top right) -&amp;gt; Monitoring Console -&amp;gt; Search -&amp;gt; Scheduler Activity: Instance, and inputting the timeframe when this occurred. Hopefully the information under "historical charts" can point you in the direction of what caused this to occur (perhaps the machine blipped, you have a misconfigured search etc), or at least narrow down the timeframe/options so you can continue debugging.&lt;/P&gt;

&lt;P&gt;Hope this helps!&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2019 16:00:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Searches-delayed/m-p/466691#M6980</guid>
      <dc:creator>aberkow</dc:creator>
      <dc:date>2019-12-17T16:00:49Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Searches delayed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Searches-delayed/m-p/466692#M6981</link>
      <description>&lt;P&gt;Hi Thanks for this, I manage to identify the issue. &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Resolution:&lt;/STRONG&gt;&lt;BR /&gt;
Increase the Limits.conf base on server information and Splunk transactions.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2020 08:27:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Searches-delayed/m-p/466692#M6981</guid>
      <dc:creator>jadengoho</dc:creator>
      <dc:date>2020-01-03T08:27:52Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Searches delayed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Searches-delayed/m-p/466693#M6982</link>
      <description>&lt;P&gt;Hi jadengoho.&lt;BR /&gt;
Can you please explain what configuration was added/extended in limits.conf  to resolve this?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2020 01:40:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Searches-delayed/m-p/466693#M6982</guid>
      <dc:creator>deepamshah</dc:creator>
      <dc:date>2020-04-07T01:40:40Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Searches delayed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Searches-delayed/m-p/505142#M8943</link>
      <description>&lt;P&gt;Even we have same issue.Can you please tell which attributes value should increase.?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2020 09:11:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Searches-delayed/m-p/505142#M8943</guid>
      <dc:creator>btshivanand</dc:creator>
      <dc:date>2020-06-19T09:11:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Searches delayed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Searches-delayed/m-p/507511#M8976</link>
      <description>&lt;P&gt;can you please tell me which attribute consider in limits.com.we have same issue.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 09:44:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Searches-delayed/m-p/507511#M8976</guid>
      <dc:creator>btshivanand</dc:creator>
      <dc:date>2020-07-06T09:44:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Searches delayed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Searches-delayed/m-p/516357#M9178</link>
      <description>&lt;P&gt;It would be great if someone helps many users who do not know the locations of the files and the parameters to configure within them.&lt;/P&gt;&lt;P&gt;In this case, where should the limits.conf configuration be applied and what are the parameters?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2020 19:06:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Searches-delayed/m-p/516357#M9178</guid>
      <dc:creator>splunkcol</dc:creator>
      <dc:date>2020-08-26T19:06:14Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Searches delayed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Searches-delayed/m-p/545632#M9827</link>
      <description>&lt;P&gt;What are the values you changed from the limits.conf?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 16:14:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Searches-delayed/m-p/545632#M9827</guid>
      <dc:creator>rmanrique</dc:creator>
      <dc:date>2021-03-26T16:14:32Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Searches delayed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Searches-delayed/m-p/548680#M9888</link>
      <description>&lt;P&gt;I found below on Reditt which fixed my issue:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.reddit.com/r/Splunk/comments/kx2bo6/splunk_searches_skipped_error/gjaak2e?utm_source=share&amp;amp;utm_medium=web2x&amp;amp;context=3" target="_blank" rel="noopener"&gt;https://www.reddit.com/r/Splunk/comments/kx2bo6/splunk_searches_skipped_error/gjaak2e?utm_source=share&amp;amp;utm_medium=web2x&amp;amp;context=3&lt;/A&gt;&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;I'm a little late to responding here but I just went thru this scenario myself. I found anytime we made any change it would cause searches to be delayed until they caught up. Before resorting to upgrading the limits.conf you need to identify what change caused Splunk to get overwhelmed. Since things are not working for you this may be a little difficult. I would recommend contacting support if you’re not comfortable with this.&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Check Correlation searches and ensure they are not set to real-time search. This would consume resources nonstop.&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Check Data Models and disable acceleration on any you may not be using. Verify time frame on the data models you leave accelerated. I found some apps had acceleration enabled with a long backfile range and that would take up a large amount of resources until it catches up.&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;I did end up working with support and received some real good clarification on CPU settings for limits.conf.&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Let me first clarify the confusion:&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;1 CPU can have 16 cores. Splunk suggest 1 search per CPU core not per CPU. The defaults are set extremely low. I’m sure that’s something that supposed to get updated during onboarding of Splunk with some professional services.&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;You will have to look at what CPU’s you have and find out how many cores each one has.&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;base_max_searches = default 6*(let max search per cpu do the work)&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;max_searches_per_cpu = if 1 CPU has 16 cores make sure to leave some room for overhead processes. So 12 would be a sweet spot.&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;max_hist_searches = max_searches_per_cpu x number_of_cpus + base_max_searches (example: 12 x 16 + 6 = 198)&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;do not modify this&lt;/EM&gt;&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;After making these changes I have not had this occur again. I've monitored CPU utilization and it has remained stable.&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Again, only do the limits.conf changes once you have figure out what is taking up so many resources. As that may just cause the server to constantly use a lot of resources. This must be configured on the search head and indexers.&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Once you get this working I do recommend using the SplunkAdmins to help identify further issues. There could be a large amount of underlying issues you may not even be aware of.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Apr 2021 20:41:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Searches-delayed/m-p/548680#M9888</guid>
      <dc:creator>sharmajiankur</dc:creator>
      <dc:date>2021-04-20T20:41:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Searches delayed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Searches-delayed/m-p/562387#M10181</link>
      <description>&lt;P&gt;In /opt/splunk/etc/system/local/limits.conf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[search]&lt;/P&gt;&lt;P&gt;max_searches_per_cpu = 12&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and then restart the splunk&lt;/P&gt;</description>
      <pubDate>Fri, 06 Aug 2021 08:23:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Searches-delayed/m-p/562387#M10181</guid>
      <dc:creator>orezaie</dc:creator>
      <dc:date>2021-08-06T08:23:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Searches delayed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Searches-delayed/m-p/564199#M10217</link>
      <description>&lt;P&gt;Also, make sure to check your firewall settings.&lt;/P&gt;</description>
      <pubDate>Sat, 21 Aug 2021 19:09:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Searches-delayed/m-p/564199#M10217</guid>
      <dc:creator>jvarner</dc:creator>
      <dc:date>2021-08-21T19:09:06Z</dc:date>
    </item>
  </channel>
</rss>

