Splunk Enterprise

What does a few "skipped searches" on a Search Head as the host indicate? Vs. an actual host like ES? Thx a million

SamHTexas
Builder

I usually get many "skipped searches" reported & the ES is indicated as the host that I understand. Lately I get many skipped searches reported but a Search Head like SH01 is indicated as the host. Please help me understand. Thank u 

Labels (1)
Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The Monitoring Console is your friend.  In the MC, select Search->Scheduler Activity: Instance then scroll down to the "Count of Skipped Reports" panels.  Choose "Report Name" from the "Group by" dropdown to see the names of the skipped searches.  If you need more information, click on the magnifying glass icon to open the search in a new tab.  Run that search in Verbose mode to see the events.  Those events will tell you which host(s) generated the events.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Skipped searches are the same whether on an ES search head or a non-ES search head.  They're bad in both places (maybe a little worse on ES), have the same causes in both places, and have the same fixes in both places.

---
If this reply helps you, Karma would be appreciated.

SamHTexas
Builder

Thanks very much as usual for your response. I had a tough time finding where the source of the saved searches are / where they are located (Which instance / Server) Any advices please?

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The Monitoring Console is your friend.  In the MC, select Search->Scheduler Activity: Instance then scroll down to the "Count of Skipped Reports" panels.  Choose "Report Name" from the "Group by" dropdown to see the names of the skipped searches.  If you need more information, click on the magnifying glass icon to open the search in a new tab.  Run that search in Verbose mode to see the events.  Those events will tell you which host(s) generated the events.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...