Splunk Search
Highlighted

Error on Real time searches "Dispatch Command: Unknown error for indexer: xxxxx"

Explorer

I have 34 realtime searches on a dashboard, whenever i open that dashboard on another user i get the error :

"Dispatch Command: Unknown error for indexer: Yggdrasil. Search Results might be incomplete! If this occurs frequently, please check on the peer."

If 2 user open that same dashboard ill have 68 realtime searches.

What could be the cause of this error and the solution?

I tried changing the maxrtsearch_multiplier but still the error exist.

0 Karma
Highlighted

Re: Error on Real time searches "Dispatch Command: Unknown error for indexer: xxxxx"

Explorer

How many CPU cores do you have on your searchhead and indexers? This message is often appearing with "bad" written searches.
Consider alternatives for real-time searches, in 99% of the cases they're really not necessary.

https://answers.splunk.com/answers/734767/why-are-realtime-searches-disliked-in-the-splunk-w.html

Here are 3 alternatives for the real-time searches:
Auto-refresh dashboard or panels

https://answers.splunk.com/answers/508962/auto-refresh-a-dashboard.html
Use scheduled searches
https://answers.splunk.com/answers/260035/what-can-we-use-to-replace-loadjob-based-dashboard.html
Write better searches:
https://docs.splunk.com/Documentation/Splunk/7.3.0/Search/Writebettersearches

0 Karma
Highlighted

Re: Error on Real time searches "Dispatch Command: Unknown error for indexer: xxxxx"

Motivator

Increase the real time search limits for your user(s) at the role level from the web UI.

alt text

0 Karma