Splunk IT Service Intelligence

Splunk IT Service Intelligence: Warning showing up after any search

zhangxq20
New Member

Hi all,

Sometimes the following warning shows up after searching no matter what search I have done.

[subsearch]: Unknown error for indexer: Indexer_03. Search Results might be incomplete! If this occurs frequently, check on the peer. 

Does anyone have any idea about it? Thanks.

0 Karma

woodcock
Esteemed Legend

Go to Settings -> Distributed search -> Search peers and see what that tells you.
Also get onto your Monitoring Console and run all of the Heath Checks and poke around on the Indexer dashboards.

0 Karma

amitm05
Builder

@zhangxq20

You are getting this error always from the same peer i.e. Indexer_03 in your case OR this is varying with your searches ?
As this might happen that the searched data is corrupted on the primary buckets of this peer.

Also, are you running dashboards OR too many queries at once ? or this is happening with singular query as well.

See this post here, it might help you -
https://answers.splunk.com/answers/506621/unknown-error-for-peer-xxx-search-results-might-be.html

0 Karma

amitm05
Builder

Can you mark as answer if your query is resolved by this OR let me know if you have further ask ?

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...