Since performing a recent upgrade, SPlunk is constantly reporting (in Health Status) that the Searches Delayed is above threshold.
E.g.The percentage of non high priority searches delayed (23%) over the last 24 hours is very high and exceeded the red thresholds (20%) on this Splunk instance. Total Searches that were part of this percentage=21. Total delayed Searches=5
In order to troubleshoot this, I need to understand what Splunk is calling a Delayed Search.
There does not seem to be any information in docs about the PeriodicHealthReporter and what it is using in relation to the data behind the results.