Hi, While troubleshooting below error message: "The percentage of non high priority searches delayed (75%) over the last 24 hours is very high and exceeded the red thresholds (20%) on this Splunk instance. Total Searches that were part of this percentage=16. Total delayed Searches=12" how can I address actual issue? ============= while looking into the system, I found out that 1- Splunk ES app is installed under /opt/splunk/etc/apps/SplunkEnterpriseSecuritySuite. Can I remove the app from above location? 2- furthermore, The output of below query is : index=_internal sourcetype=scheduler savedsearch_name=* status=skipped | stats count BY reason 1- Error in 'SearchParser': The search specifies a macro 'notable' that cannot be found. Reasons include: the macro name is misspelled, you do not have... 2-The maximum number of concurrent running jobs for this historical scheduled search on this instance has been reached ================= I found that
... View more