Reporting

SavedSplunker - Max alive instance count=1 reached for saved search_id

mlevsh
Builder

Hi,
We are running Splunk v. 7.0.1
We are getting the following warning on our search heads

"Max alive instance_count=1 reached for saved savedsearch_id="user;search;SearchName"

What does it mean and how to correct this issue?

Thank you!

1 Solution

elliotproebstel
Champion

This error is generated when you have a saved search that is scheduled to run on a recurring basis and Splunk tries to start the search on schedule but discovers that a previous instance of this search is still running. For example, let's say you were to save a query that takes an hour to complete and schedule it to run every ten minutes. Splunk would start the first iteration and then try to start another iteration ten minutes later, but it would see that the first iteration was still running - so it would generate this error message and not start the second iteration. It will generate one of these messages every time it tries to start the saved search and discovers that a previous instance is still running.

View solution in original post

elliotproebstel
Champion

This error is generated when you have a saved search that is scheduled to run on a recurring basis and Splunk tries to start the search on schedule but discovers that a previous instance of this search is still running. For example, let's say you were to save a query that takes an hour to complete and schedule it to run every ten minutes. Splunk would start the first iteration and then try to start another iteration ten minutes later, but it would see that the first iteration was still running - so it would generate this error message and not start the second iteration. It will generate one of these messages every time it tries to start the saved search and discovers that a previous instance is still running.

mlevsh
Builder

@elliotproebstel, thank you so much for the explanation.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...