Troubleshoot with integrated splunkd health report
The Summary dashboard in the Monitoring Console lets you troubleshoot health issues with your Splunk Enterprise deployment that the splunkd health report detects.
Investigate feature health issues
The Anomalies panel in the Summary dashboard lists splunkd health report features that are currently in the red or yellow state. Features in the red or yellow state can indicate a serious issue with your deployment. Use the Anomalies panel to review descriptions of each issue, and access health checks to investigate root cause.
To investigate feature health issues:
- Click Settings > Monitoring Console > Summary.
- In the Anomalies panel, review the descriptions of listed features in the read and yellow state.
- To further investigate a specific issue, click Investigate.
The Health Check page open. The page shows recommended health checks relating to the reported issue. - Run the recommended health checks to get information on root cause and suggested fixes for the issue.
Example: Investigate skipped searches
This example illustrates how to use the Summary dashboard to troubleshoot a critical health status issue detected by the splunkd health report.
- Click Settings > Monitoring Console > Summary.
- In the Anomalies panel, the "skipped searches" feature appears in the critical "red" state.
This indicates that there is a severe issue that is negatively impacting search performance. - Review the description provided by the splunkd health report for basic information about the issue.
- Click Investigate.
The Health Check page opens showing health checks recommended for investigating "Search scheduler skip ratio", "Orphaned scheduled searches", and "resource usage". - Run the recommended health checks.
The "Search scheduler skip ratio" health check fails. - Click on the failed health check to view the health check results, information about the cause of the problem, and suggested actions for fixing the problem.
- See the following Monitoring Console dashboards to perform further root cause analysis: Search > Scheduler Activity: Instance/Deployment, Resource Usage: Instance/Deployment.
For more information on updatable health checks, see Download health check updates.
For more information on the splunkd
health report, see About pro-active Splunk component monitoring.
This documentation applies to the following versions of Splunk® Enterprise: 8.0.0, 8.0.1, 8.0.2, 8.0.3, 8.0.4, 8.0.5, 8.0.6, 8.0.7, 8.0.8, 8.0.9, 8.0.10, 8.1.0, 8.1.1, 8.1.2, 8.1.3, 8.1.4, 8.1.5, 8.1.6, 8.1.7, 8.1.8, 8.1.9, 8.1.10, 8.1.11, 8.1.12, 8.1.13, 8.1.14
Feedback submitted, thanks!