Dashboards & Visualizations

Why are the real-time searches frozen?

robertosegantin
Path Finder

In my Splunk Enterprise environment, I have many real-time searches to monitor many servers ad web applications.
Every real-time searches process about 10k events, over 5m or 10m window, and their results are displayed on a dashboard which is checked by many people and many wallboards.

Unfortunately, in last days, often the real-time searches became frozen, indeed the dashboard is not updated automatically and I have to kill and restart the processes under "Activity > Jobs"

On _internal index, or others, I'm not able to find any error or a particular warning.

Does someone have any idea how to debug this behavior?

0 Karma
Get Updates on the Splunk Community!

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...

Get ready to show some Splunk Certification swagger at .conf24!

Dive into the deep end of data by earning a Splunk Certification at .conf24. We're enticing you again this ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Now On-Demand Join us to learn more about how you can leverage Service Level Objectives (SLOs) and the new ...