In my Splunk Enterprise environment, I have many real-time searches to monitor many servers ad web applications.
Every real-time searches process about 10k events, over 5m or 10m window, and their results are displayed on a dashboard which is checked by many people and many wallboards.
Unfortunately, in last days, often the real-time searches became frozen, indeed the dashboard is not updated automatically and I have to kill and restart the processes under "Activity > Jobs"
On _internal index, or others, I'm not able to find any error or a particular warning.
Does someone have any idea how to debug this behavior?