Dashboards & Visualizations

Why are the real-time searches frozen?

robertosegantin
Path Finder

In my Splunk Enterprise environment, I have many real-time searches to monitor many servers ad web applications.
Every real-time searches process about 10k events, over 5m or 10m window, and their results are displayed on a dashboard which is checked by many people and many wallboards.

Unfortunately, in last days, often the real-time searches became frozen, indeed the dashboard is not updated automatically and I have to kill and restart the processes under "Activity > Jobs"

On _internal index, or others, I'm not able to find any error or a particular warning.

Does someone have any idea how to debug this behavior?

0 Karma
Get Updates on the Splunk Community!

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...