Monitoring Splunk

Splunk Health Report warning is not going away

anel
Explorer

Hi all,

5 days ago we got an issue with delayed searches. 

This is fixed and we did not have skipped or delayed searches since. However, the warning is not disappearing. 

Is there a way to manually trigger a recheck, mark this as acknowledged or any other way of making this warning go away? 

anel_1-1714395008598.png

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @anel,

tis health check is related to the last 24 hours, are you sure that in this period you don't have delayed searches?

You can check this in the Monitoring Console.

Anyway, it's not possible to reset this alert, you have only to wait for the time.

Ciao.

Giuseppe

anel
Explorer

Hey Guiseppe, 

Thanks for replying. Yeah we did not have delayed searches in the last 24h. 

One day later we still have exactly the same numbers.

anel_0-1714464306481.png

 

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @anel ,

you could go in [Settings > Health Report Manager+ and change the threshold of the latency controls, even if in my mind the issue will disappear in few time.

Ciao.

Giuseppe

0 Karma

anel
Explorer

A restart of the SHC resolved the issue 

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...