<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Health Check (Warning, Info and N/A) in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Health-Check-Warning-Info-and-N-A/m-p/322024#M159975</link>
    <description>&lt;P&gt;Hi Guys,&lt;/P&gt;

&lt;P&gt;Good Day!&lt;/P&gt;

&lt;P&gt;Regarding on our Splunk servers, we've performed a health check and we found some warning, info and n/a status. Just want to  ask what this are and how this result impacts on our application. Please see below screenshot.&lt;/P&gt;

&lt;P&gt;Thank you!&lt;BR /&gt;
Kevin&lt;/P&gt;</description>
    <pubDate>Fri, 21 Jul 2017 03:51:24 GMT</pubDate>
    <dc:creator>vino06</dc:creator>
    <dc:date>2017-07-21T03:51:24Z</dc:date>
    <item>
      <title>Splunk Health Check (Warning, Info and N/A)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Health-Check-Warning-Info-and-N-A/m-p/322024#M159975</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;

&lt;P&gt;Good Day!&lt;/P&gt;

&lt;P&gt;Regarding on our Splunk servers, we've performed a health check and we found some warning, info and n/a status. Just want to  ask what this are and how this result impacts on our application. Please see below screenshot.&lt;/P&gt;

&lt;P&gt;Thank you!&lt;BR /&gt;
Kevin&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2017 03:51:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Health-Check-Warning-Info-and-N-A/m-p/322024#M159975</guid>
      <dc:creator>vino06</dc:creator>
      <dc:date>2017-07-21T03:51:24Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Health Check (Warning, Info and N/A)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Health-Check-Warning-Info-and-N-A/m-p/322025#M159976</link>
      <description>&lt;P&gt;Hi Kevin!&lt;/P&gt;

&lt;P&gt;The actions you should take are dependent on which nodes are involved and require some knowledge about your environment, but I'll do my best to set you in the right direction here. &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;ULIMITS &amp;amp; THP&lt;/STRONG&gt;&lt;BR /&gt;
For the System and Environment warnings, it is telling you that THP and ulimits are not optimally set for a Splunk Enterprise instance. I would only be worried about correcting this in your core Splunk nodes (Indexers, Search Heads, etc....anything other than Universal Forwarders, really). &lt;/P&gt;

&lt;P&gt;Here is some documentation on THP and Ulimits. How you these depends on your system, so work with your sysadmins to ensure they are set persistently. &lt;/P&gt;

&lt;P&gt;About Ulimit - &lt;A href="https://docs.splunk.com/Documentation/Splunk/6.6.2/Troubleshooting/ulimitErrors"&gt;https://docs.splunk.com/Documentation/Splunk/6.6.2/Troubleshooting/ulimitErrors&lt;/A&gt;&lt;BR /&gt;
Example How to adjust - &lt;A href="https://www.tecmint.com/increase-set-open-file-limits-in-linux/"&gt;https://www.tecmint.com/increase-set-open-file-limits-in-linux/&lt;/A&gt;&lt;BR /&gt;
* note in the versions of RHEL i have played with lately, setting the ulimits on boot-start can be tricky, consult your vendor docs if necessary. &lt;/P&gt;

&lt;P&gt;About THP - &lt;A href="https://docs.splunk.com/Documentation/Splunk/6.6.2/ReleaseNotes/SplunkandTHP"&gt;https://docs.splunk.com/Documentation/Splunk/6.6.2/ReleaseNotes/SplunkandTHP&lt;/A&gt;&lt;BR /&gt;
Example How to Disable THP in Centos 7 - &lt;A href="https://newbiedba.wordpress.com/2015/09/07/disabling-transparent-huge-pages-in-centos-7-x/"&gt;https://newbiedba.wordpress.com/2015/09/07/disabling-transparent-huge-pages-in-centos-7-x/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Missing Forwarders&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Missing forwarders is simply forwarders that have not been seen in the last 15 minutes by your indexers. You can see more on this in Forwarder Management dashboard and can be resolved by rebuilding your forwarder lookup if need be. This may or may not be impacting you depending on whether they are decommissioned servers, etc. You will need to &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Skipped Searches&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;This is something you will need to look at in your search heads. You can use the Monitoring Console to analyze your search performance. There is a good break down on what is being skipped under Settings &amp;gt; Monitoring Console &amp;gt; Search &amp;gt; Search Activity: Instance&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2017 14:18:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Health-Check-Warning-Info-and-N-A/m-p/322025#M159976</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2017-07-21T14:18:23Z</dc:date>
    </item>
  </channel>
</rss>

