Reporting

SavedSplunker - Max alive instance count=1 reached for saved search_id

mlevsh
Builder

Hi,
We are running Splunk v. 7.0.1
We are getting the following warning on our search heads

"Max alive instance_count=1 reached for saved savedsearch_id="user;search;SearchName"

What does it mean and how to correct this issue?

Thank you!

1 Solution

elliotproebstel
Champion

This error is generated when you have a saved search that is scheduled to run on a recurring basis and Splunk tries to start the search on schedule but discovers that a previous instance of this search is still running. For example, let's say you were to save a query that takes an hour to complete and schedule it to run every ten minutes. Splunk would start the first iteration and then try to start another iteration ten minutes later, but it would see that the first iteration was still running - so it would generate this error message and not start the second iteration. It will generate one of these messages every time it tries to start the saved search and discovers that a previous instance is still running.

View solution in original post

elliotproebstel
Champion

This error is generated when you have a saved search that is scheduled to run on a recurring basis and Splunk tries to start the search on schedule but discovers that a previous instance of this search is still running. For example, let's say you were to save a query that takes an hour to complete and schedule it to run every ten minutes. Splunk would start the first iteration and then try to start another iteration ten minutes later, but it would see that the first iteration was still running - so it would generate this error message and not start the second iteration. It will generate one of these messages every time it tries to start the saved search and discovers that a previous instance is still running.

mlevsh
Builder

@elliotproebstel, thank you so much for the explanation.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...