Dashboards & Visualizations

Why are the real-time searches frozen?

robertosegantin
Path Finder

In my Splunk Enterprise environment, I have many real-time searches to monitor many servers ad web applications.
Every real-time searches process about 10k events, over 5m or 10m window, and their results are displayed on a dashboard which is checked by many people and many wallboards.

Unfortunately, in last days, often the real-time searches became frozen, indeed the dashboard is not updated automatically and I have to kill and restart the processes under "Activity > Jobs"

On _internal index, or others, I'm not able to find any error or a particular warning.

Does someone have any idea how to debug this behavior?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...