Deployment Architecture

What does status=delegated_remote OR status=delegated_remote_completion mean in the scheduler log?

ben_leung
Builder

If looking at scheduler log from a single search head in the search head cluster, what does status=delegated_remote OR status=delegated_remote_completion mean? Does it mean that the search that was running to the current search head move to another search peer to run and complete?

jcrabb_splunk
Splunk Employee
Splunk Employee

This is logged on the captain in scheduler.log when a remote job is delegated to a member and when a remote delegated job is completed on a member.

Jacob
Sr. Technical Support Engineer

BP9906
Builder

How do you determine the peer the search was sent to?
I have a 2 peer SH cluster and the captain says status=delegated_remote and we received no alert. Not to mention that the other peer (not captain) is configured to be adhoc searching only. So why did the captain delegate it?

0 Karma

sowings
Splunk Employee
Splunk Employee

member_label / member_guid / member_uri from the same message. I've seen the captain report that it delegated a search to itself.

0 Karma

awilliams_splun
Splunk Employee
Splunk Employee

How do you have a two peer SHC? At least 3 Search heads are required.

0 Karma

ben_leung
Builder

I have not yet seen the scheduler skip a search yet... Wondering how the log looks like when it does skip... Anyone experience this in SHC yet?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...