<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Search results might be incomplete: the search process on the local peer:%s ended prematurely. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Search-results-might-be-incomplete-the-search-process-on-the/m-p/617702#M214667</link>
    <description>&lt;P&gt;I found this in the splunkd.log on one of the splunk indexers at the time of the error message&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;10-18-2022 11:00:17.141 +0000 ERROR SearchProcessRunner [2379030 PreforkedSearchesManager-0] - preforked process=0/437059 hung up&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;10-18-2022 11:00:17.163 +0000 WARN&amp;nbsp;&amp;nbsp;SearchProcessRunner [2379030 PreforkedSearchesManager-0] - preforked process=0/437059 status=killed, signum=9, signame="Killed", coredump=0, utime_sec=1.672967, stime_sec=0.285628, max_rss_kb=207912, vm_minor=72863, fs_r_count=6352, fs_w_count=456, sched_vol=407, sched_invol=1431&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Is this a Swap memory issue?&lt;/P&gt;</description>
    <pubDate>Wed, 19 Oct 2022 13:44:44 GMT</pubDate>
    <dc:creator>RichieH</dc:creator>
    <dc:date>2022-10-19T13:44:44Z</dc:date>
    <item>
      <title>Search results might be incomplete: the search process on the local peer:%s ended prematurely?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-results-might-be-incomplete-the-search-process-on-the/m-p/617673#M214660</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;When running a search the following error will appear in the job inspector. Users get this message intermittently on searches. No results can be returned.&lt;/P&gt;
&lt;PRE&gt;10-18-2022 11:00:22.349 ERROR DispatchThread [3247729 phase_1] - code=10 error=""
10-18-2022 11:00:22.349 ERROR ResultsCollationProcessor [3247729 phase_1] - SearchMessage orig_component= sid=1666090813.341131_7E89B3C6-34D5-44DA-B19C-E6A755245D39 message_key=DISPATCHCOMM:PEER_PIPE_EXCEPTION__%s message=Search results might be incomplete: the search process on the peer:pldc1splindex1 ended prematurely. Check the peer log, such as $SPLUNK_HOME/var/log/splunk/splunkd.log and as well as the search.log for the particular search.&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;The message.conf shows&lt;/P&gt;
&lt;P&gt;[DISPATCHCOMM:PEER_PIPE_EXCEPTION__S]&lt;BR /&gt;message = Search results might be incomplete: the search process on the local peer:%s ended prematurely.&lt;BR /&gt;action = Check the local peer log, such as $SPLUNK_HOME/var/log/splunk/splunkd.log and as well as the search.log for the particular search.&lt;BR /&gt;severity = warn&lt;/P&gt;
&lt;P&gt;I also have Splunk Alerts that are showing false positives, the alert search is retuning no results but the Splunk&amp;nbsp;sourcetype=scheduler is sending out emails with success?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is this related?&lt;/P&gt;
&lt;P&gt;What does this mean?&amp;nbsp;PEER_PIPE_EXCEPTION__S&lt;/P&gt;
&lt;P&gt;Splunk Enterprise OnPrem version 9.0.1 on a distributed environment.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 14:26:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-results-might-be-incomplete-the-search-process-on-the/m-p/617673#M214660</guid>
      <dc:creator>RichieH</dc:creator>
      <dc:date>2022-10-19T14:26:33Z</dc:date>
    </item>
    <item>
      <title>Re: Search results might be incomplete: the search process on the local peer:%s ended prematurely.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-results-might-be-incomplete-the-search-process-on-the/m-p/617685#M214662</link>
      <description>&lt;P&gt;Did you look at splunkd.conf on the peer as well as search.log like the error suggested?&amp;nbsp; What did you find there?&lt;/P&gt;&lt;P&gt;Messages.conf is not a troubleshooting aid.&amp;nbsp; It's for assigning severities to log messages.&amp;nbsp; "&lt;SPAN&gt;PEER_PIPE_EXCEPTION__S" identifies the type of error encountered.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 12:34:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-results-might-be-incomplete-the-search-process-on-the/m-p/617685#M214662</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-10-19T12:34:44Z</dc:date>
    </item>
    <item>
      <title>Re: Search results might be incomplete: the search process on the local peer:%s ended prematurely.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-results-might-be-incomplete-the-search-process-on-the/m-p/617702#M214667</link>
      <description>&lt;P&gt;I found this in the splunkd.log on one of the splunk indexers at the time of the error message&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;10-18-2022 11:00:17.141 +0000 ERROR SearchProcessRunner [2379030 PreforkedSearchesManager-0] - preforked process=0/437059 hung up&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;10-18-2022 11:00:17.163 +0000 WARN&amp;nbsp;&amp;nbsp;SearchProcessRunner [2379030 PreforkedSearchesManager-0] - preforked process=0/437059 status=killed, signum=9, signame="Killed", coredump=0, utime_sec=1.672967, stime_sec=0.285628, max_rss_kb=207912, vm_minor=72863, fs_r_count=6352, fs_w_count=456, sched_vol=407, sched_invol=1431&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Is this a Swap memory issue?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 13:44:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-results-might-be-incomplete-the-search-process-on-the/m-p/617702#M214667</guid>
      <dc:creator>RichieH</dc:creator>
      <dc:date>2022-10-19T13:44:44Z</dc:date>
    </item>
    <item>
      <title>Re: Search results might be incomplete: the search process on the local peer:%s ended prematurely.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-results-might-be-incomplete-the-search-process-on-the/m-p/617707#M214671</link>
      <description>&lt;P&gt;It could be a memory issue.&amp;nbsp; Check /var/log/messages on the peer for OOM Killer events.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 14:04:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-results-might-be-incomplete-the-search-process-on-the/m-p/617707#M214671</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-10-19T14:04:15Z</dc:date>
    </item>
    <item>
      <title>Re: Search results might be incomplete: the search process on the local peer:%s ended prematurely.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-results-might-be-incomplete-the-search-process-on-the/m-p/617726#M214679</link>
      <description>&lt;P&gt;Indeed there was such messages in DMESG on the Indexers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've had to&amp;nbsp;&lt;STRONG&gt;Disable Swap Memory &lt;/STRONG&gt;: &amp;nbsp;sqapoff -a&amp;nbsp;&lt;/P&gt;&lt;P&gt;and done a rolling restart across the indexers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your time on this.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 16:29:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-results-might-be-incomplete-the-search-process-on-the/m-p/617726#M214679</guid>
      <dc:creator>RichieH</dc:creator>
      <dc:date>2022-10-19T16:29:14Z</dc:date>
    </item>
  </channel>
</rss>

