Splunk Search

How do I investigate delayed searched reported in Health status under Splunkd

SamHTexas
Builder

I keep getting delayed searches marked in red "Health Status - Splunkd". How do I investigate and fix this issue?

Tags (1)
0 Karma

tscroggins
Influencer

@SamHTexas 

The simplest method is the local monitoring console. Click Settings > Monitoring Console. In the app bar, click Search > Scheduler Activity: Instance. In the Historical Charts section of the dashboard, you can see various panels related to search scheduling.

If you find many deferred searches, you have three options:

1. Optimize scheduled searches.
2. Adjust limits. See https://docs.splunk.com/Documentation/Splunk/latest/Admin/Limitsconf#Concurrency.
3. Add CPUs. (This is often Splunk's recommendation, but try optimization first.)

0 Karma

SamHTexas
Builder

Thank u. In the historical section.  I see "no results found" and 0 for total historical chart area ( at bottom left). No matter what I change in the time range or group by items, nothing happens. Please advise.

Tags (1)
0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...