Getting Data In

Splunk Health Warning on Search Head

Roy_9
Motivator

Hello,

We are using Splunk cloud and seeing the below error message on SH.

 Search Scheduler Search Lag

  • Root Cause(s):
    • The number of extremely lagged searches (4) over the last hour exceeded the red threshold (1) on this Splunk instance

 

Can someone please help me in fixing this issue?

 

 

Thanks

Labels (3)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Use the Cloud Monitoring Console app to see which searches are lagged.  Go to Search->Scheduler Activity and scroll down to the Execution Latency panel.  Group the results by Report Name to find the offending searches.

Try rescheduling the searches to a time when fewer other searches are running.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...

AppDynamics is now part of Splunk Ideas

Hello Splunkers, We have exciting news for you! AppDynamics has been added to the Splunk Ideas Portal. Which ...

Advanced Splunk Data Management Strategies

Join us on Wednesday, May 14, 2025, at 11 AM PDT / 2 PM EDT for an exclusive Tech Talk that delves into ...