Splunk Enterprise

What does a few "skipped searches" on a Search Head as the host indicate? Vs. an actual host like ES? Thx a million

SamHTexas
Builder

I usually get many "skipped searches" reported & the ES is indicated as the host that I understand. Lately I get many skipped searches reported but a Search Head like SH01 is indicated as the host. Please help me understand. Thank u 

Labels (1)
Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The Monitoring Console is your friend.  In the MC, select Search->Scheduler Activity: Instance then scroll down to the "Count of Skipped Reports" panels.  Choose "Report Name" from the "Group by" dropdown to see the names of the skipped searches.  If you need more information, click on the magnifying glass icon to open the search in a new tab.  Run that search in Verbose mode to see the events.  Those events will tell you which host(s) generated the events.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Skipped searches are the same whether on an ES search head or a non-ES search head.  They're bad in both places (maybe a little worse on ES), have the same causes in both places, and have the same fixes in both places.

---
If this reply helps you, Karma would be appreciated.

SamHTexas
Builder

Thanks very much as usual for your response. I had a tough time finding where the source of the saved searches are / where they are located (Which instance / Server) Any advices please?

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The Monitoring Console is your friend.  In the MC, select Search->Scheduler Activity: Instance then scroll down to the "Count of Skipped Reports" panels.  Choose "Report Name" from the "Group by" dropdown to see the names of the skipped searches.  If you need more information, click on the magnifying glass icon to open the search in a new tab.  Run that search in Verbose mode to see the events.  Those events will tell you which host(s) generated the events.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...