<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Dispatch Alert Question in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Dispatch-Alert-Question/m-p/445494#M126368</link>
    <description>&lt;P&gt;all, &lt;/P&gt;

&lt;P&gt;I am getting a dispatch count alert . Indexers and search heads have plenty of RAM, CPU and IO is almost nothing. I can't think of a reason for this to start to backup. Honestly the environment is under almost no load. &lt;/P&gt;

&lt;P&gt;My knee jerk here is to increase the jobs per CPU count. But wondering what others think here?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Dispatch Command: The number of search artifacts in the dispatch directory is higher than recommended (count=6444, warning threshold=5000) and could have an impact on search performance. Remove excess search artifacts using the "splunk clean-dispatch" CLI command, and review artifact retention policies in limits.conf and savedsearches.conf. You can also raise this warning threshold in limits.conf / dispatch_dir_warning_size.
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Wed, 26 Dec 2018 17:34:17 GMT</pubDate>
    <dc:creator>daniel333</dc:creator>
    <dc:date>2018-12-26T17:34:17Z</dc:date>
    <item>
      <title>Dispatch Alert Question</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Dispatch-Alert-Question/m-p/445494#M126368</link>
      <description>&lt;P&gt;all, &lt;/P&gt;

&lt;P&gt;I am getting a dispatch count alert . Indexers and search heads have plenty of RAM, CPU and IO is almost nothing. I can't think of a reason for this to start to backup. Honestly the environment is under almost no load. &lt;/P&gt;

&lt;P&gt;My knee jerk here is to increase the jobs per CPU count. But wondering what others think here?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Dispatch Command: The number of search artifacts in the dispatch directory is higher than recommended (count=6444, warning threshold=5000) and could have an impact on search performance. Remove excess search artifacts using the "splunk clean-dispatch" CLI command, and review artifact retention policies in limits.conf and savedsearches.conf. You can also raise this warning threshold in limits.conf / dispatch_dir_warning_size.
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 26 Dec 2018 17:34:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Dispatch-Alert-Question/m-p/445494#M126368</guid>
      <dc:creator>daniel333</dc:creator>
      <dc:date>2018-12-26T17:34:17Z</dc:date>
    </item>
    <item>
      <title>Re: Dispatch Alert Question</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Dispatch-Alert-Question/m-p/445495#M126369</link>
      <description>&lt;P&gt;Did you try cleaning dispatch directory?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Dec 2018 07:36:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Dispatch-Alert-Question/m-p/445495#M126369</guid>
      <dc:creator>p_gurav</dc:creator>
      <dc:date>2018-12-27T07:36:33Z</dc:date>
    </item>
    <item>
      <title>Re: Dispatch Alert Question</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Dispatch-Alert-Question/m-p/445496#M126370</link>
      <description>&lt;P&gt;&lt;STRONG&gt;this solution i think work buddy&lt;/STRONG&gt;&lt;BR /&gt;
./splunk clean-dispatch run the command&lt;BR /&gt;
splunkd clean-dispatch '' ''&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2019 06:21:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Dispatch-Alert-Question/m-p/445496#M126370</guid>
      <dc:creator>zippyopsadmin</dc:creator>
      <dc:date>2019-10-16T06:21:05Z</dc:date>
    </item>
    <item>
      <title>Re: Dispatch Alert Question</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Dispatch-Alert-Question/m-p/445497#M126371</link>
      <description>&lt;P&gt;could you please let me know where should i clean is it in indexer or search head ? i got message on one of the dev search head  saying that "search peer has following message " . so , where should i run the below command if clean dispatch is it impacts anything ?&lt;/P&gt;</description>
      <pubDate>Sat, 16 May 2020 16:14:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Dispatch-Alert-Question/m-p/445497#M126371</guid>
      <dc:creator>90509</dc:creator>
      <dc:date>2020-05-16T16:14:42Z</dc:date>
    </item>
  </channel>
</rss>

