- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Introspection
Hello I am running search
index=_introspection
dedup host
table host
in result i am not able to see one indexer and one search head while other indexers and sh are visible .
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Hi @SN1
If you look further back, when was the last event?
Have a look using this search looking back at least to the time of the last event from the missing servers.
| tstats latest(_time) as _time where index=_introspection by host
Then run the search 5-10 minutes later. Are the times of the last events different for the missing host? If so this would suggest that they are having issues sending logs and that they are delayed, rather than not sending at all.
In addition it would be worth checking the Splunk log of the missing host directly, check out $SPLUNK_HOME/var/log/splunk/splunkd.log - are there any references to blocking or output errors?
Please let me know how you get on and consider adding karma to this or any other answer if it has helped.
Regards
Will
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Check that there is enough storage on the volume containing the introspection index.
Also, confirm no one turned off introspection. See
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you run this search, how many peers return count?
index=_internal earliest=-5m@m | stats count by splunk_server
This should give responses from all your indexers, and if you have your SH / Component boxes configured to forward their internal logs, those also.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- The hosts are down or disconnected.
- The Splunk instance on those hosts is not running.
- There’s a network issue preventing data from being forwarded.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
i am getting this error on health check
- Root Cause(s):
- Events from tracker.log have not been seen for the last 238401 seconds, which is more than the red threshold (210 seconds). This typically occurs when indexing or forwarding are falling behind or are blocked.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The _introspection index in Splunk is part of the "Platform Instrumentation" features, which collect information about your systems running Splunk to help diagnose performance issues.
What does platform instrumentation log? - Splunk Documentation
Introspection endpoint descriptions - Splunk Documentation
