Hi All,
Recently I have noticed that some of the our Saved Searches are failing with the errors like below,
"Failed to start search for id="scheduler__abcde__Qk1TX1dNX0lOVEdfTUVUUklDUw__RMD57438a1f3bbe5dac6_at_1588593600_88844". Dropping failedtostart token at path=/opt/splunk/var/run/splunk/dispatch/scheduler__abcde_Qk1TX1dNX0lOVEdfTUVUUklDUw__RMD57438a1f3bbe5dac6_at_1588593600_88844 to expedite dispatch cleanup
Could anyone suggest what could be the issue ?
Take a look at the scheduler log. I don't have any time-outs on my system so I don't what specifically to look for, but index=_internal source=*scheduler.log status!=success
is a good start.
Scheduler log tells you about skipped and successful searches but does not tell you about timeouts.