Splunk Enterprise Security

With regards to PeriodicHealthReporter, what constitutes a "Delayed Search"

michael_bates_1
Path Finder

Since performing a recent upgrade, SPlunk is constantly reporting (in Health Status) that the Searches Delayed is above threshold.

E.g.The percentage of non high priority searches delayed (23%) over the last 24 hours is very high and exceeded the red thresholds (20%) on this Splunk instance. Total Searches that were part of this percentage=21. Total delayed Searches=5

In order to troubleshoot this, I need to understand what Splunk is calling a Delayed Search.

There does not seem to be any information in docs about the PeriodicHealthReporter and what it is using in relation to the data behind the results.