Splunk Enterprise

What does a few "skipped searches" on a Search Head as the host indicate? Vs. an actual host like ES? Thx a million

SamHTexas
Builder

I usually get many "skipped searches" reported & the ES is indicated as the host that I understand. Lately I get many skipped searches reported but a Search Head like SH01 is indicated as the host. Please help me understand. Thank u 

Labels (1)
Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The Monitoring Console is your friend.  In the MC, select Search->Scheduler Activity: Instance then scroll down to the "Count of Skipped Reports" panels.  Choose "Report Name" from the "Group by" dropdown to see the names of the skipped searches.  If you need more information, click on the magnifying glass icon to open the search in a new tab.  Run that search in Verbose mode to see the events.  Those events will tell you which host(s) generated the events.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Skipped searches are the same whether on an ES search head or a non-ES search head.  They're bad in both places (maybe a little worse on ES), have the same causes in both places, and have the same fixes in both places.

---
If this reply helps you, Karma would be appreciated.

SamHTexas
Builder

Thanks very much as usual for your response. I had a tough time finding where the source of the saved searches are / where they are located (Which instance / Server) Any advices please?

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The Monitoring Console is your friend.  In the MC, select Search->Scheduler Activity: Instance then scroll down to the "Count of Skipped Reports" panels.  Choose "Report Name" from the "Group by" dropdown to see the names of the skipped searches.  If you need more information, click on the magnifying glass icon to open the search in a new tab.  Run that search in Verbose mode to see the events.  Those events will tell you which host(s) generated the events.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...