After enabling the Distributed Management Console on an Enterprise Security (ES) search head, searches stop returning results. The following additional behaviors were also experienced.
Navigation to the Settings menu in the UI is slow but works.
When trying to access the Search UI, Splunk does not respond.
Running a search from the command line does not return results.
The “Scheduled time” value in “Settings > Searches, reports, and alerts” contains dates from the past.
Large gaps in time (more than 24 hours in some cases) were seen in the scheduler.log and splunkd.log files.
Why is this happening?
... View more