Splunk Enterprise

What does a few "skipped searches" on a Search Head as the host indicate? Vs. an actual host like ES? Thx a million

SamHTexas
Builder

I usually get many "skipped searches" reported & the ES is indicated as the host that I understand. Lately I get many skipped searches reported but a Search Head like SH01 is indicated as the host. Please help me understand. Thank u 

Labels (1)
Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The Monitoring Console is your friend.  In the MC, select Search->Scheduler Activity: Instance then scroll down to the "Count of Skipped Reports" panels.  Choose "Report Name" from the "Group by" dropdown to see the names of the skipped searches.  If you need more information, click on the magnifying glass icon to open the search in a new tab.  Run that search in Verbose mode to see the events.  Those events will tell you which host(s) generated the events.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Skipped searches are the same whether on an ES search head or a non-ES search head.  They're bad in both places (maybe a little worse on ES), have the same causes in both places, and have the same fixes in both places.

---
If this reply helps you, Karma would be appreciated.

SamHTexas
Builder

Thanks very much as usual for your response. I had a tough time finding where the source of the saved searches are / where they are located (Which instance / Server) Any advices please?

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The Monitoring Console is your friend.  In the MC, select Search->Scheduler Activity: Instance then scroll down to the "Count of Skipped Reports" panels.  Choose "Report Name" from the "Group by" dropdown to see the names of the skipped searches.  If you need more information, click on the magnifying glass icon to open the search in a new tab.  Run that search in Verbose mode to see the events.  Those events will tell you which host(s) generated the events.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...