Splunk Searches Skipped on the Cluster master console error messages
@isoutamo After identifying those searches, what is the process to remove the warning message, since we are seeing the similar kind of issue on our SH where our SH health is red.
Does a SH cluster restart help?
After you have identified those, you also see what was the reason for that. Then just fix the reason one by one. That could be e.g. too many search at same time => reschedule, no permission to indexed/run => fix permission/change ownership etc.
You should check what those are from MC (Settings - Monitoring Console - Searches - Schedule searches). There you can see when, where and what those are.
r. Ismo