Getting Data In

How to detect cause & source of Search delays on Splunk Ent. In a clustered SH + Indexer environment. Thank u

SamHTexas
Builder

This includes High priority mostly. How do I view a list & provide a solution please. The error indicating the delays shows up as error message on the Ent. & even the ES server we have. Thanks a million.

Labels (1)
Tags (1)
0 Karma

tshah-splunk
Splunk Employee
Splunk Employee

There's a dashboard in Monitoring Console which displays the list of scheduled searches, their skip ratio and also the reason for them being skipped. You can navigate to it from Settings -> Monitoring Console -> Search -> Scheduler Activity -> Scheduler Activity: Instance

Under this dashboard when you scroll down, there's a panel named "Count of Skipped Reports by Name and Reason

Let me know if this helps your objective.

---
If you find the answer helpful, an upvote/karma is appreciated

SamHTexas
Builder

How would I do this on the ES? Does the MC has to be in Distributed mode? Thx a bunch.

Tags (1)
0 Karma

tshah-splunk
Splunk Employee
Splunk Employee

Monitoring Console can work on Standalone mode as well. If you want the whole environment to be monitored via Monitoring Console, then all the Splunk Components should be added as distributed search peer to the monitoring console. You can find the related information here - https://docs.splunk.com/Documentation/Splunk/8.2.4/DMC/Addinstancesassearchpeers
https://docs.splunk.com/Documentation/Splunk/8.2.4/DMC/Deploymentsetupsteps 

To configure monitoring console for standalone environment, find reference here - https://docs.splunk.com/Documentation/Splunk/8.2.4/DMC/Configureinstandalonemode 
https://docs.splunk.com/Documentation/Splunk/8.2.4/DMC/Singleinstancesetup 

---
If you find the answer helpful, an upvote/karma is appreciated
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...