Reporting

Scheduled searches no longer running, showing Scheduled Time in the past.

hanoc
Engager

We have numerous searches that are supposed to run every minute.

They have run successfully for months now, but yesterday we found that they had suddenly stopped doing the Summary Indexing they are supposed to and the scheduled time on the "Manager -> Searches and Reports" page is in the past at the same point as the summary index stops being added to.

If i check in the scheduler.log I can see the search being run with status=success before during and after the time mentioned on the Searches and Reports page.

Any ideas on why this could be happening?

Tags (1)
0 Karma

tnesavich
Engager

I believe you are likely using search head clustering and or pooling and the captain is out of synch. To fix this:

  1. Identify your captain: http://docs.splunk.com/Documentation/Splunk/6.2.3/DistSearch/SHCdeploymentoverview#Check_search_head...
  2. Bounce the captain (Splunk Stop / Start)
  3. Confirm your Scheduled searches all have future dates.
0 Karma
Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...