Since performing a recent upgrade, SPlunk is constantly reporting (in Health Status) that the Searches Delayed is above threshold.
E.g.The percentage of non high priority searches delayed (23%) over the last 24 hours is very high and exceeded the red thresholds (20%) on this Splunk instance. Total Searches that were part of this percentage=21. Total delayed Searches=5
In order to troubleshoot this, I need to understand what Splunk is calling a Delayed Search.
There does not seem to be any information in docs about the PeriodicHealthReporter and what it is using in relation to the data behind the results.
I am also getting the same error on Splunk health check after recent upgrade.
The percentage of non high priority searches delayed (23%) over the last 24 hours is very high and exceeded the red thresholds (20%) on this Splunk instance. Total Searches that were part of this percentage=948. Total delayed Searches=224
Highly appreciate, if you could share the remediation steps if the issue was fixed.
Thanks in advance