Deployment Architecture

Splunk Health Check warnings- How to resolve?

harimadambi
Explorer

alt textHi All,

I'm receiving Distributed search health assessment warning while performing the Health Check in Splunk 6.6.8
Mine is a multi-clustered environment with totally 5 search heads and cluster master which is also identified as a search head by Splunk. I'm receiving the warning for cluster master.

For more information about the warning message, please see the attached images.

Could anyone please help me on why I'm receiving this warning message and what actions I should take to resolve this issue?]1

Thank You!

Labels (1)
0 Karma

Peterman
Explorer

@harimadambi wrote:

alt textHi All,

I'm receiving Distributed search health assessment warning while performing the Health Check in Splunk 6.6.8
Mine is a multi-clustered environment with totally 5 search heads and cluster master which is also identified as a search head by Splunk. I'm receiving the warning for cluster master.

For more information about the warning message, please see the attached images.

Could anyone please help me on why I'm receiving this warning message and what actions I should take to resolve this issue?]1 

Thank You!


that is very informative man i love the comment 

0 Karma

DavidHourani
Super Champion

Hi @harimadambi,

Distributed search health assessment warning is linked to : Search Peer Not Responding. It checks the status of the search peers (indexers) of each search head.

It could be that one of your indexers is unreachable for one of the search heads. Or was down during this health check. Check the _internal logs for that search head to see any connection failure to the indexers. In your case it's very possible that your CM is defined as a search head but is unable to reach all search peers that are configured on it.

Cheers,
David

0 Karma

sittipornbaycom
Loves-to-Learn Lots

We have issues same you. if you solving problems please help me. Thank you

0 Karma

richgalloway
SplunkTrust
SplunkTrust

It's saying your cluster master has one search peer (indexer) in a degraded state. Have you tried the Suggested Action?

---
If this reply helps you, Karma would be appreciated.
0 Karma

harimadambi
Explorer

@richgalloway Thank you for your input. It seems all my search peers are up and in healthy state. I'll check further on this.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...