<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Randomly problems when execute a search in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Randomly-problems-when-execute-a-search/m-p/491652#M8372</link>
    <description>&lt;P&gt;Hi, &lt;/P&gt;

&lt;P&gt;you need to find the root cause for the error. On the splunk UI, dropdown "Job" and select "Inspect Job" to open the job inspector of a failed query. In the Job inspector window, look for the "search.log" link and click it. In the log, search for the words "WARN" or "ERROR"&lt;/P&gt;

&lt;P&gt;Once you know the root cause for the problem, we could probably help you to avoid it in the future.&lt;/P&gt;

&lt;P&gt;Hope it helps,&lt;BR /&gt;
Oliver&lt;/P&gt;</description>
    <pubDate>Wed, 06 May 2020 14:14:11 GMT</pubDate>
    <dc:creator>ololdach</dc:creator>
    <dc:date>2020-05-06T14:14:11Z</dc:date>
    <item>
      <title>Randomly problems when execute a search</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Randomly-problems-when-execute-a-search/m-p/491651#M8371</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Since a few months I have random problems when I try to execute a search that works correctly.&lt;BR /&gt;
The problem is that sometimes the job of the search returns the following exception:&lt;/P&gt;

&lt;P&gt;"""&lt;BR /&gt;
X errors occurred while the search was executing. Therefore, search results might be incomplete.&lt;BR /&gt;
Dispatch Command: Unknown error for indexer: my_search_head_0X. Search Results might be incomplete! If this occurs frequently, please check on the peer.&lt;BR /&gt;
"""&lt;/P&gt;

&lt;P&gt;This error show up problems in each Search Head that I have. &lt;BR /&gt;
How I said this is random because if I try to execute again the same query after the error it shows me the results.&lt;/P&gt;

&lt;P&gt;Anybody can help me to fix this or understand why is happening this.&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 05:18:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Randomly-problems-when-execute-a-search/m-p/491651#M8371</guid>
      <dc:creator>splunk_soc360</dc:creator>
      <dc:date>2020-09-30T05:18:45Z</dc:date>
    </item>
    <item>
      <title>Re: Randomly problems when execute a search</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Randomly-problems-when-execute-a-search/m-p/491652#M8372</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;

&lt;P&gt;you need to find the root cause for the error. On the splunk UI, dropdown "Job" and select "Inspect Job" to open the job inspector of a failed query. In the Job inspector window, look for the "search.log" link and click it. In the log, search for the words "WARN" or "ERROR"&lt;/P&gt;

&lt;P&gt;Once you know the root cause for the problem, we could probably help you to avoid it in the future.&lt;/P&gt;

&lt;P&gt;Hope it helps,&lt;BR /&gt;
Oliver&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2020 14:14:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Randomly-problems-when-execute-a-search/m-p/491652#M8372</guid>
      <dc:creator>ololdach</dc:creator>
      <dc:date>2020-05-06T14:14:11Z</dc:date>
    </item>
  </channel>
</rss>

