<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: The percentage of non high priority searches skipped (50%) in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-percentage-of-non-high-priority-searches-skipped-50/m-p/591605#M205943</link>
    <description>&lt;P&gt;I understand how those settings work, but they aren't set on the indexers. Seems like there should be no limit to search unless max_count is a limit, which you are saying it isn't. Is there a hard-coded limit in the Splunk code somewhere?&lt;/P&gt;</description>
    <pubDate>Wed, 30 Mar 2022 18:36:16 GMT</pubDate>
    <dc:creator>timpacl</dc:creator>
    <dc:date>2022-03-30T18:36:16Z</dc:date>
    <item>
      <title>Why is the percentage of non high priority searches skipped (50%) is high?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-percentage-of-non-high-priority-searches-skipped-50/m-p/480823#M134729</link>
      <description>&lt;P&gt;The percentage of non high priority searches skipped (50%) over the last 24 hours is very high and exceeded the red thresholds (20%) on this Splunk instance. Total Searches that were part of this percentage=2. Total skipped Searches=1&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 17:02:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-percentage-of-non-high-priority-searches-skipped-50/m-p/480823#M134729</guid>
      <dc:creator>dejiosemeke</dc:creator>
      <dc:date>2022-03-30T17:02:49Z</dc:date>
    </item>
    <item>
      <title>Re: The percentage of non high priority searches skipped (50%)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-percentage-of-non-high-priority-searches-skipped-50/m-p/480824#M134730</link>
      <description>&lt;P&gt;What is your question?&lt;/P&gt;</description>
      <pubDate>Mon, 20 Apr 2020 14:26:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-percentage-of-non-high-priority-searches-skipped-50/m-p/480824#M134730</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-04-20T14:26:41Z</dc:date>
    </item>
    <item>
      <title>Re: The percentage of non high priority searches skipped (50%)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-percentage-of-non-high-priority-searches-skipped-50/m-p/591508#M205916</link>
      <description>&lt;P&gt;I see this error reported by indexers. That seems wrong since a "skipped" search is never dispatched to an indexer. Am I misunderstanding the message? "&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;The&lt;/SPAN&gt; &lt;SPAN class=""&gt;percentage&lt;/SPAN&gt; &lt;SPAN class=""&gt;of&lt;/SPAN&gt; &lt;SPAN class=""&gt;non&lt;/SPAN&gt; &lt;SPAN class=""&gt;high&lt;/SPAN&gt; &lt;SPAN class=""&gt;priority&lt;/SPAN&gt; &lt;SPAN class=""&gt;searches&lt;/SPAN&gt; &lt;SPAN class=""&gt;skipped&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class=""&gt;33%&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class=""&gt;over&lt;/SPAN&gt; &lt;SPAN class=""&gt;the&lt;/SPAN&gt; &lt;SPAN class=""&gt;last&lt;/SPAN&gt; &lt;SPAN class=""&gt;24&lt;/SPAN&gt; &lt;SPAN class=""&gt;hours&lt;/SPAN&gt; &lt;SPAN class=""&gt;is&lt;/SPAN&gt; &lt;SPAN class=""&gt;very&lt;/SPAN&gt; &lt;SPAN class=""&gt;high&lt;/SPAN&gt; &lt;SPAN class=""&gt;and&lt;/SPAN&gt; &lt;SPAN class=""&gt;exceeded&lt;/SPAN&gt; &lt;SPAN class=""&gt;the&lt;/SPAN&gt; &lt;SPAN class=""&gt;red&lt;/SPAN&gt; &lt;SPAN class=""&gt;thresholds&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class=""&gt;20%&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;on&lt;/SPAN&gt; &lt;SPAN class=""&gt;this&lt;/SPAN&gt; &lt;SPAN class=""&gt;Splunk&lt;/SPAN&gt; &lt;/STRONG&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;instance&lt;/STRONG&gt;."&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 13:53:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-percentage-of-non-high-priority-searches-skipped-50/m-p/591508#M205916</guid>
      <dc:creator>timpacl</dc:creator>
      <dc:date>2022-03-30T13:53:27Z</dc:date>
    </item>
    <item>
      <title>Re: The percentage of non high priority searches skipped (50%)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-percentage-of-non-high-priority-searches-skipped-50/m-p/591516#M205918</link>
      <description>&lt;P&gt;Not really. There are two separate limits that you have to take into accounts when dealing with searches.&lt;/P&gt;&lt;P&gt;One is the limit of concurrent searches at search-head. And another one is the limit at indexer.&lt;/P&gt;&lt;P&gt;So if you have several search-heads (clustered or not), they can have their limits set high enough that the combined searches from several search-heads exceed the limit set for the indexer. The searches then can be delayed or skipped.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 14:04:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-percentage-of-non-high-priority-searches-skipped-50/m-p/591516#M205918</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-03-30T14:04:30Z</dc:date>
    </item>
    <item>
      <title>Re: The percentage of non high priority searches skipped (50%)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-percentage-of-non-high-priority-searches-skipped-50/m-p/591557#M205931</link>
      <description>&lt;P&gt;Thanks for the response. Interesting. Splunk PS told us that indexers don't have a search limit. Do you know when the search limit was implemented for indexers? Where it is configured?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 15:37:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-percentage-of-non-high-priority-searches-skipped-50/m-p/591557#M205931</guid>
      <dc:creator>timpacl</dc:creator>
      <dc:date>2022-03-30T15:37:06Z</dc:date>
    </item>
    <item>
      <title>Re: The percentage of non high priority searches skipped (50%)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-percentage-of-non-high-priority-searches-skipped-50/m-p/591577#M205935</link>
      <description>&lt;P&gt;Of course in limits.conf &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.5/Admin/Limitsconf#Concurrency" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.5/Admin/Limitsconf#Concurrency&lt;/A&gt;&lt;/P&gt;&lt;P&gt;As far as I understand, those limits apply both to search heads and indexers.&lt;/P&gt;&lt;P&gt;You have to remember that indexer uses some part of its capacity for indexing process (typically 4-6CPUs per indexing pipeline if I remember correctly) so you have less CPUs available for searching.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 17:03:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-percentage-of-non-high-priority-searches-skipped-50/m-p/591577#M205935</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-03-30T17:03:46Z</dc:date>
    </item>
    <item>
      <title>Re: The percentage of non high priority searches skipped (50%)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-percentage-of-non-high-priority-searches-skipped-50/m-p/591587#M205938</link>
      <description>&lt;P&gt;Thanks. Running btool on an indexer returns settings that aren't mentioned in the docs and none of the settings that are mentioned in the docs:&lt;/P&gt;&lt;P&gt;Documentation&lt;/P&gt;&lt;PRE&gt;&lt;SPAN class=""&gt;Concurrency&lt;/SPAN&gt;&lt;/PRE&gt;&lt;PRE&gt;base_max_searches = &amp;lt;integer&amp;gt;
max_rt_search_multiplier = &amp;lt;decimal number&amp;gt;
max_searches_per_cpu = &amp;lt;integer&amp;gt;&lt;/PRE&gt;&lt;P&gt;Indexer "splunk btool limits list concurrency --debug" (all setting returned from &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;BR /&gt;/opt/splunk/etc/system/default/limits.conf [concurrency]&lt;BR /&gt;/opt/splunk/etc/system/default/limits.conf&amp;nbsp; &lt;STRONG&gt;max_count = 10000000&lt;/STRONG&gt;&lt;BR /&gt;/opt/splunk/etc/system/default/limits.conf&amp;nbsp; max_mem_usage_mb = 200&lt;/P&gt;&lt;P&gt;So, if this is right, my indexers would be trying to run in excess of 10M searches concurrently. We have been tracking daily searches and we are doing 2M/day. Even if subsearches and the like are factored in, I don't see how we could hit 10M concurrent searches.&lt;/P&gt;&lt;P&gt;Thanks for helping with this. It has provided direction to look.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 17:17:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-percentage-of-non-high-priority-searches-skipped-50/m-p/591587#M205938</guid>
      <dc:creator>timpacl</dc:creator>
      <dc:date>2022-03-30T17:17:04Z</dc:date>
    </item>
    <item>
      <title>Re: The percentage of non high priority searches skipped (50%)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-percentage-of-non-high-priority-searches-skipped-50/m-p/591592#M205939</link>
      <description>&lt;P&gt;No, max_count is a different story.&lt;/P&gt;&lt;P&gt;You want these parameters:&lt;/P&gt;&lt;PRE&gt;base_max_searches = &amp;lt;integer&amp;gt;
* A constant to add to the maximum number of searches, computed as a
  multiplier of the CPUs.
* Default: 6

max_rt_search_multiplier = &amp;lt;decimal number&amp;gt;
* A number by which the maximum number of historical searches is multiplied
  to determine the maximum number of concurrent real-time searches.
* NOTE: The maximum number of real-time searches is computed as:
  max_rt_searches = max_rt_search_multiplier x max_hist_searches
* Default: 1

max_searches_per_cpu = &amp;lt;integer&amp;gt;
* The maximum number of concurrent historical searches for each CPU.
  The system-wide limit of historical searches is computed as:
  max_hist_searches =  max_searches_per_cpu x number_of_cpus + base_max_searches
* NOTE: The maximum number of real-time searches is computed as:
  max_rt_searches = max_rt_search_multiplier x max_hist_searches
* Default: 1&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 17:24:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-percentage-of-non-high-priority-searches-skipped-50/m-p/591592#M205939</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-03-30T17:24:29Z</dc:date>
    </item>
    <item>
      <title>Re: The percentage of non high priority searches skipped (50%)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-percentage-of-non-high-priority-searches-skipped-50/m-p/591605#M205943</link>
      <description>&lt;P&gt;I understand how those settings work, but they aren't set on the indexers. Seems like there should be no limit to search unless max_count is a limit, which you are saying it isn't. Is there a hard-coded limit in the Splunk code somewhere?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 18:36:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-percentage-of-non-high-priority-searches-skipped-50/m-p/591605#M205943</guid>
      <dc:creator>timpacl</dc:creator>
      <dc:date>2022-03-30T18:36:16Z</dc:date>
    </item>
    <item>
      <title>Re: The percentage of non high priority searches skipped (50%)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-percentage-of-non-high-priority-searches-skipped-50/m-p/591613#M205947</link>
      <description>&lt;P&gt;You're checking in the wrong section.&lt;/P&gt;&lt;P&gt;The [concurrency] stanza is for something different. The settings we're talking about are indeed concurrency settings but within the [search] stanza.&lt;/P&gt;&lt;P&gt;And they are perfectly well defined in system/default/limits.conf.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 19:25:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-percentage-of-non-high-priority-searches-skipped-50/m-p/591613#M205947</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-03-30T19:25:49Z</dc:date>
    </item>
    <item>
      <title>Re: The percentage of non high priority searches skipped (50%)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-percentage-of-non-high-priority-searches-skipped-50/m-p/591619#M205949</link>
      <description>&lt;P&gt;If the search stanza settings are being applied then each indexer would be limited to 30 concurrent searches with the default settings (which is what we have). We asked Splunk Professional Services about that and they said these limits weren't enforced on the indexers. Rough math says that if every search ran was just 1 second duration a would be limited to 2.5M searches/day. As I said, we are doing 2M/day now and our searches aren't all 1 sec. Last year we had a peak at 3.25M searches/day.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 19:56:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-percentage-of-non-high-priority-searches-skipped-50/m-p/591619#M205949</guid>
      <dc:creator>timpacl</dc:creator>
      <dc:date>2022-03-30T19:56:17Z</dc:date>
    </item>
    <item>
      <title>Re: The percentage of non high priority searches skipped (50%)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-percentage-of-non-high-priority-searches-skipped-50/m-p/591709#M205975</link>
      <description>&lt;P&gt;OK. It seems strange. On the one hand, it does indeed seem to not be enforced - I lowered it to 0 (zero!) per cpu and just 1 base search. Which should give me just one available search per indexer.&lt;/P&gt;&lt;P&gt;I'm still able to run three parallel real-time searches against my indexers even though my monitoring console says that the limit is 1 search. But the utilization is 3/1 &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;So it might indeed not be enforced. Sorry for confusion then.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2022 07:42:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-percentage-of-non-high-priority-searches-skipped-50/m-p/591709#M205975</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-03-31T07:42:07Z</dc:date>
    </item>
  </channel>
</rss>

