Splunk Search

large delay between dispatch_time and scheduled_time in shc - SHCRepJob failed

schose
Builder

Hi forum,

we are facing large increasing delays between dispatch_time and scheduled_time in scheduler log. We see delays up to 200 seconds for searches which are scheduled every minute - resulting in not-scheduled searches.

this directly correlates to "ERROR SHCRepJob - failed to delegate job job=SHPDelegateSearchJob peer="peername", guid="466C6F6D-2779-4BFD-AE1F-64A71D0A5AC8" saved_search=system;; err="
messages we see at the SHC Captain.

Any hints? Other Single-Search-head instances do not show any issues. Using v.7.1.6

Best Regards,

Andreas

0 Karma

harsmarvania57
Ultra Champion

Hi,

Have you looked at scheduler.log on your Search Head Cluster Members ?

Below query will help you to identify why captain failed to delegate job to SHC members.

index=_internal host IN(SH1,SH2,SH3) sourcetype=scheduler status=delegated_remote_error
0 Karma
Get Updates on the Splunk Community!

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...

Everything Community at .conf24!

You may have seen mention of the .conf Community Zone 'round these parts and found yourself wondering what ...

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...