Installation

Why am I seeing a higher skipped/deferred in my search head cluster after upgrading to 9.x ?

rphillips_splk
Splunk Employee
Splunk Employee

I recently upgraded my search head cluster to 9.x and since then my skipped/deferred searches have sky rocketed.

 

 

index=_internal source=*scheduler.log  
status=* | timechart span=60s count by status

 

 

 

Labels (1)
Tags (2)
0 Karma

rphillips_splk
Splunk Employee
Splunk Employee

Please see this knowledge article for details on the known issue and fix/workaround:
https://splunk.my.site.com/customer/s/article/High-Skipped-Search-Ratio-after-upgrading-to-9-x

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.0.2 Availability: On cloud and On-premise!

A few months ago, we released Splunk Enterprise Security 8.0 for our cloud customers. Today, we are excited to ...

Logs to Metrics

Logs and Metrics Logs are generally unstructured text or structured events emitted by applications and written ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...