Splunk IT Service Intelligence

Splunk IT Service Intelligence: Warning showing up after any search

zhangxq20
New Member

Hi all,

Sometimes the following warning shows up after searching no matter what search I have done.

[subsearch]: Unknown error for indexer: Indexer_03. Search Results might be incomplete! If this occurs frequently, check on the peer. 

Does anyone have any idea about it? Thanks.

0 Karma

woodcock
Esteemed Legend

Go to Settings -> Distributed search -> Search peers and see what that tells you.
Also get onto your Monitoring Console and run all of the Heath Checks and poke around on the Indexer dashboards.

0 Karma

amitm05
Builder

@zhangxq20

You are getting this error always from the same peer i.e. Indexer_03 in your case OR this is varying with your searches ?
As this might happen that the searched data is corrupted on the primary buckets of this peer.

Also, are you running dashboards OR too many queries at once ? or this is happening with singular query as well.

See this post here, it might help you -
https://answers.splunk.com/answers/506621/unknown-error-for-peer-xxx-search-results-might-be.html

0 Karma

amitm05
Builder

Can you mark as answer if your query is resolved by this OR let me know if you have further ask ?

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...