Search: Scheduler Activity
This topic is a reference for the Scheduler Activity dashboards in the Monitoring Console. See About the Monitoring Console.
What do these dashboards show?
The Scheduler activity: Deployment dashboard shows an overview of the search or report scheduler. The instance dashboard shows more detailed information about the scheduler on a particular instance.
These dashboards show activity and success rate of the scheduler. That is, of all the searches that attempted to run, how many succeeded? A scheduled search can fail because of concurrency problems or because of a search workload.
The panels in these dashboards qualify the type of failure. Skip ratio and execution latency quantify the scheduler's performance.
The scheduler activity dashboards are useful whether or not you are using search head clustering. If you have a search head cluster, you can also use the Search head clustering: Scheduler delegation dashboard, which deals with how the captain orchestrates scheduler jobs.
Interpret results in these dashboards
In the deployment dashboard, the Statistics panel describes how the scheduler is performing per instance, but including all instances in the deployment. For example, maximum is the maximum on any individual instance in the deployment.
What to look for in these dashboards
If your scheduler reaches the maximum allowed concurrent searches, you will run into problems scheduling additional or long-running searches. See Configure the priority of scheduled reports for more information.
The snapshot quantities skip ratio and average execution latency should both be low.
The following is an example Scheduler activity: Instance panel for a scheduler that is skipping reports.
To find why the scheduler is skipping reports, scroll down to the panel labeled Count of skipped reports by name and reason.
Troubleshoot these dashboards
The scheduler activity dashboards require the monitored instances to be running Splunk Enterprise 6.3.0 or later.
Make sure you have completed all of the Monitoring Console setup steps.
Search: KV Store
Search: Distributed Search
This documentation applies to the following versions of Splunk® Enterprise: 6.5.0, 6.5.1, 6.5.1612 (Splunk Cloud only), 6.5.2, 6.5.3, 6.5.4, 6.5.5, 6.5.6, 6.5.7, 6.5.8, 6.5.9, 6.5.10, 6.6.0, 6.6.1, 6.6.2, 6.6.3, 6.6.4, 6.6.5, 6.6.6, 6.6.7, 6.6.8, 6.6.9, 6.6.10, 6.6.11, 6.6.12, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6, 7.0.7, 7.0.8, 7.0.9, 7.0.10, 7.1.0, 7.1.1, 7.1.2, 7.1.3, 7.1.4, 7.1.5, 7.1.6, 7.1.7, 7.1.8, 7.2.0, 7.2.1, 7.2.2, 7.2.3, 7.2.4, 7.2.5, 7.2.6, 7.2.7, 7.3.0