Getting Data In

"Returned partial results" error message

shivanandbm
Explorer

Indexer Clustering: The search process with sid=rt_md_1533830226.207365 on peer=XXXXXX may have returned partial results due to a reading error while waiting for the peer. This can occur if the peer unexpectedly closes or resets the connection during a planned restart. Try running the search again. Learn more.

0 Karma

dm1
Contributor

were you able to fix this issue? if yes, please share solution. Thanks.

0 Karma

woodcock
Esteemed Legend

If you cannot talk to all of your defined search peers, then you will get this message. Go to Config -> Distributed Search -> Search Peers and you will see that one is sick or at some other non-Healthy value. Sometimes the problem can be resolved by deleting and re-peering.

DalJeanis
Legend

The error message says exactly what it means. If you try running the search repeatedly and keep getting this issue, then you may have an error in the connection path. For example, if you are on a multi-site clustered system, then perhaps the VPN link to the other site is wobbly, or perhaps some firewall in between is messing with the connection. Or, perhaps it is exactly what is says it might be, and the indexer restarted during the time that the search was running.

If this is happening to a job consistently at night, but not when you rerun during the day, try moving the job forward or backward to avoid the time that the indexer in question goes wonky.

In any case, this is not generally going to be a problem with your SPL (your search), rather it is some kind of problem with the architecture of your cluster or the timing of the job, relative to maintenance windows. See your system admins to ask them what they think it might be.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

What is your question?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...