Splunk Search

Error on Real time searches "Dispatch Command: Unknown error for indexer: xxxxx"

ygdrassilp
Explorer

I have 34 realtime searches on a dashboard, whenever i open that dashboard on another user i get the error :

"Dispatch Command: Unknown error for indexer: Yggdrasil. Search Results might be incomplete! If this occurs frequently, please check on the peer."

If 2 user open that same dashboard ill have 68 realtime searches.

What could be the cause of this error and the solution?

I tried changing the max_rt_search_multiplier but still the error exist.

0 Karma

codebuilder
Influencer

Increase the real time search limits for your user(s) at the role level from the web UI.

alt text

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma

micheldejong
Explorer

How many CPU cores do you have on your searchhead and indexers? This message is often appearing with "bad" written searches.
Consider alternatives for real-time searches, in 99% of the cases they're really not necessary.

https://answers.splunk.com/answers/734767/why-are-realtime-searches-disliked-in-the-splunk-w.html

Here are 3 alternatives for the real-time searches:
Auto-refresh dashboard or panels

https://answers.splunk.com/answers/508962/auto-refresh-a-dashboard.html
Use scheduled searches
https://answers.splunk.com/answers/260035/what-can-we-use-to-replace-loadjob-based-dashboard.html
Write better searches:
https://docs.splunk.com/Documentation/Splunk/7.3.0/Search/Writebettersearches

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...