<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Co-relation search in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Co-relation-search/m-p/464355#M3903</link>
    <description>&lt;P&gt;I have two co-relation search in ITSI which is scheduled to 15 minutes of windows, what is the appropriate scheduled should be set to avoid any performance issue in future.&lt;/P&gt;</description>
    <pubDate>Sat, 06 Jun 2020 01:07:06 GMT</pubDate>
    <dc:creator>friend444</dc:creator>
    <dc:date>2020-06-06T01:07:06Z</dc:date>
    <item>
      <title>Co-relation search</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Co-relation-search/m-p/464355#M3903</link>
      <description>&lt;P&gt;I have two co-relation search in ITSI which is scheduled to 15 minutes of windows, what is the appropriate scheduled should be set to avoid any performance issue in future.&lt;/P&gt;</description>
      <pubDate>Sat, 06 Jun 2020 01:07:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Co-relation-search/m-p/464355#M3903</guid>
      <dc:creator>friend444</dc:creator>
      <dc:date>2020-06-06T01:07:06Z</dc:date>
    </item>
    <item>
      <title>Re: Co-relation search</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Co-relation-search/m-p/464356#M3904</link>
      <description>&lt;P&gt;There are no definitive answers, it depends on your search time, the server concurrency load, and the desired time to be notified of alerts or the frequency.&lt;/P&gt;

&lt;P&gt;Example : you run 2 correlation searches running every 15 minutes, looking back at 15 minutes.&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;If the searchest take 10 seconds to execute, then it will not count on your search concurrency as 2 jobs for 10 seconds every 15 min.&lt;/LI&gt;
&lt;LI&gt;If the searches take 20 minutes to run, then it will persistently count at 2 job concurrencies, plus every 15 min, you will have an overlap, and it will count at 4...&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;If you have an alert condition happening t=0, then the correlation search runs as t=10m, then it will take you 10 minutes to be get a notable alert created, and a few seconds to get grouped in an Episode and trigger an action. &lt;BR /&gt;
Changing the frequency will help control the time before you are notified, it may vary based on the type of data you are monitoring,&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2020 22:47:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Co-relation-search/m-p/464356#M3904</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2020-02-03T22:47:24Z</dc:date>
    </item>
  </channel>
</rss>

