<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Background Search query in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Background-Search-query/m-p/670736#M229905</link>
    <description>&lt;P&gt;That particular error is referring to a hiccup during the execution of the search with the&amp;nbsp;&lt;EM&gt;search peers&lt;/EM&gt; - aka the Splunk Indexers - that were involved in your query.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is a diagram of a simple Splunk enterprise deployment - you were initiating your query on a Search Head, and that query is shared out to the Indexer(s) that make up your deployment.&amp;nbsp; It sounds like one of the Indexers had an issue:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunk_deploy.jpg" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/28359i553E1117BDDA2729/image-size/medium?v=v2&amp;amp;px=400" role="button" title="splunk_deploy.jpg" alt="splunk_deploy.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;To find more info on what your issue is, you can open your search results, and click on the Inspect Job option under the Job menu on the result page:&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunk_job_inspect.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/28361i93647B133903A419/image-size/medium?v=v2&amp;amp;px=400" role="button" title="splunk_job_inspect.png" alt="splunk_job_inspect.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And then open the search.log from the Job Inspector page that pops up:&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunk_search_log.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/28362i01636DDF5C964495/image-size/medium?v=v2&amp;amp;px=400" role="button" title="splunk_search_log.png" alt="splunk_search_log.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Within that log file that opens you can find more details on what happened during your search to trigger the warning message "&lt;SPAN&gt;Search results might be incomplete" that you saw.&lt;BR /&gt;&lt;BR /&gt;If you have more info on any of the error/warning logs in that file we could help you figure out what could be causing your issue.&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 04 Dec 2023 23:47:35 GMT</pubDate>
    <dc:creator>_JP</dc:creator>
    <dc:date>2023-12-04T23:47:35Z</dc:date>
    <item>
      <title>Background Search query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Background-Search-query/m-p/670699#M229897</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a Splunk search query executing the in the background(used Send to background option) while this is running my VPN got disconnected and after sometime I have reconnected to VPN and the query is still runing in the background. My question is does it gives me complete results or any incomplete results?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2023 18:51:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Background-Search-query/m-p/670699#M229897</guid>
      <dc:creator>Siya</dc:creator>
      <dc:date>2023-12-04T18:51:02Z</dc:date>
    </item>
    <item>
      <title>Re: Background Search query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Background-Search-query/m-p/670701#M229898</link>
      <description>&lt;P&gt;You should have complete results based on your description and a couple of assumptions:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am assuming that you are connecting to a remote Splunk instance (probably a Search Head (SH) - aka the Splunk website), and you are not running Splunk locally on your computer.&amp;nbsp; In that case, you would have complete results.&amp;nbsp; Your computer does not have to stay connected to a Splunk SH for a background search to complete properly.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2023 19:19:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Background-Search-query/m-p/670701#M229898</guid>
      <dc:creator>_JP</dc:creator>
      <dc:date>2023-12-04T19:19:50Z</dc:date>
    </item>
    <item>
      <title>Re: Background Search query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Background-Search-query/m-p/670702#M229899</link>
      <description>&lt;P&gt;Thanks for your response.&lt;/P&gt;&lt;P&gt;I have received this error message along with the results.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;Search results might be incomplete! This can occur if the peer unexpectedly closes or resets the connection during a planned restart. Try running your search again.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2023 19:27:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Background-Search-query/m-p/670702#M229899</guid>
      <dc:creator>Siya</dc:creator>
      <dc:date>2023-12-04T19:27:09Z</dc:date>
    </item>
    <item>
      <title>Re: Background Search query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Background-Search-query/m-p/670736#M229905</link>
      <description>&lt;P&gt;That particular error is referring to a hiccup during the execution of the search with the&amp;nbsp;&lt;EM&gt;search peers&lt;/EM&gt; - aka the Splunk Indexers - that were involved in your query.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is a diagram of a simple Splunk enterprise deployment - you were initiating your query on a Search Head, and that query is shared out to the Indexer(s) that make up your deployment.&amp;nbsp; It sounds like one of the Indexers had an issue:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunk_deploy.jpg" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/28359i553E1117BDDA2729/image-size/medium?v=v2&amp;amp;px=400" role="button" title="splunk_deploy.jpg" alt="splunk_deploy.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;To find more info on what your issue is, you can open your search results, and click on the Inspect Job option under the Job menu on the result page:&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunk_job_inspect.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/28361i93647B133903A419/image-size/medium?v=v2&amp;amp;px=400" role="button" title="splunk_job_inspect.png" alt="splunk_job_inspect.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And then open the search.log from the Job Inspector page that pops up:&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunk_search_log.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/28362i01636DDF5C964495/image-size/medium?v=v2&amp;amp;px=400" role="button" title="splunk_search_log.png" alt="splunk_search_log.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Within that log file that opens you can find more details on what happened during your search to trigger the warning message "&lt;SPAN&gt;Search results might be incomplete" that you saw.&lt;BR /&gt;&lt;BR /&gt;If you have more info on any of the error/warning logs in that file we could help you figure out what could be causing your issue.&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2023 23:47:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Background-Search-query/m-p/670736#M229905</guid>
      <dc:creator>_JP</dc:creator>
      <dc:date>2023-12-04T23:47:35Z</dc:date>
    </item>
  </channel>
</rss>

