Our Splunk SH cluster scheduler stopping, users complaining that alerts/scheduled reporting not running or processing. We disabled and enabled the scheduler on the captain but that didnt work. We decided to switch captaincy to another and that worked - scheduling/processing resumed. Today we had reoccurrence but on a different Search head cluster - we switched captains and that remediated issue again.
Version 8.0.6 and recent change - cascading bundle replication enabled around a month ago.