<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help on Correlation search scheduling in Security</title>
    <link>https://community.splunk.com/t5/Security/Help-on-Correlation-search-scheduling/m-p/705219#M18240</link>
    <description>&lt;P&gt;I have about 800 searches. some that run take more than a minute.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;so in the messages it states: status: skipped, reason: "The maximum number of concurrent auto-summarization searches on this instance has been reached. "&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;no warnings or errors. all messages have "INFO" right after date/time&lt;BR /&gt;&lt;BR /&gt;cpu usage is at about 12% and memory usage is at 28%&lt;/P&gt;</description>
    <pubDate>Mon, 25 Nov 2024 18:30:33 GMT</pubDate>
    <dc:creator>ajmach343</dc:creator>
    <dc:date>2024-11-25T18:30:33Z</dc:date>
    <item>
      <title>Help on Correlation search scheduling</title>
      <link>https://community.splunk.com/t5/Security/Help-on-Correlation-search-scheduling/m-p/705215#M18238</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;I am currently building correlation searches in ES and I am running into a "searches delayed" issue. some of my searches run every hour, most are every 2 hours, and some every 3, 12 hours.&lt;/P&gt;&lt;P&gt;My time range looks like:&lt;/P&gt;&lt;P&gt;Earliest Time: -2h&amp;nbsp;&lt;BR /&gt;Latest Time: now&lt;/P&gt;&lt;P&gt;cron schedule: 1 */2 * * *&lt;BR /&gt;&lt;BR /&gt;for each new search I add +1 to the minute tab of the cron schedule up to 59 and then start over.&amp;nbsp;&lt;BR /&gt;so on the next search the schedule would be 2 */2 * * * and so on...&lt;BR /&gt;&lt;BR /&gt;is there a more efficient way I should be scheduling searches?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 18:04:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Help-on-Correlation-search-scheduling/m-p/705215#M18238</guid>
      <dc:creator>ajmach343</dc:creator>
      <dc:date>2024-11-25T18:04:28Z</dc:date>
    </item>
    <item>
      <title>Re: Help on Correlation search scheduling</title>
      <link>https://community.splunk.com/t5/Security/Help-on-Correlation-search-scheduling/m-p/705218#M18239</link>
      <description>&lt;P&gt;No that should be fine. As long as you have enough CPU and threads and your correlation searches are not overlapping with its next execution (e.g. if the search runs every 2 hours but it takes 2.5 hours to complete), then you use the +1 minute technique to spread the searches around, then it should be fine.&lt;/P&gt;&lt;P&gt;Do you get warnings about concurrent searches or do you see high CPU usage in your monitoring console?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 18:16:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Help-on-Correlation-search-scheduling/m-p/705218#M18239</guid>
      <dc:creator>marnall</dc:creator>
      <dc:date>2024-11-25T18:16:39Z</dc:date>
    </item>
    <item>
      <title>Re: Help on Correlation search scheduling</title>
      <link>https://community.splunk.com/t5/Security/Help-on-Correlation-search-scheduling/m-p/705219#M18240</link>
      <description>&lt;P&gt;I have about 800 searches. some that run take more than a minute.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;so in the messages it states: status: skipped, reason: "The maximum number of concurrent auto-summarization searches on this instance has been reached. "&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;no warnings or errors. all messages have "INFO" right after date/time&lt;BR /&gt;&lt;BR /&gt;cpu usage is at about 12% and memory usage is at 28%&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 18:30:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Help-on-Correlation-search-scheduling/m-p/705219#M18240</guid>
      <dc:creator>ajmach343</dc:creator>
      <dc:date>2024-11-25T18:30:33Z</dc:date>
    </item>
  </channel>
</rss>

