Splunk IT Service Intelligence

Splunk IT Service Intelligence: Warning showing up after any search

zhangxq20
New Member

Hi all,

Sometimes the following warning shows up after searching no matter what search I have done.

[subsearch]: Unknown error for indexer: Indexer_03. Search Results might be incomplete! If this occurs frequently, check on the peer. 

Does anyone have any idea about it? Thanks.

0 Karma

woodcock
Esteemed Legend

Go to Settings -> Distributed search -> Search peers and see what that tells you.
Also get onto your Monitoring Console and run all of the Heath Checks and poke around on the Indexer dashboards.

0 Karma

amitm05
Builder

@zhangxq20

You are getting this error always from the same peer i.e. Indexer_03 in your case OR this is varying with your searches ?
As this might happen that the searched data is corrupted on the primary buckets of this peer.

Also, are you running dashboards OR too many queries at once ? or this is happening with singular query as well.

See this post here, it might help you -
https://answers.splunk.com/answers/506621/unknown-error-for-peer-xxx-search-results-might-be.html

0 Karma

amitm05
Builder

Can you mark as answer if your query is resolved by this OR let me know if you have further ask ?

0 Karma
Get Updates on the Splunk Community!

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...

Adoption of Infrastructure Monitoring at Splunk

  Splunk's Growth Engineering team showcases one of their first Splunk product adoption-Splunk Infrastructure ...

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...