<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Search killing _audit in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Search-killing-audit/m-p/483321#M4007</link>
    <description>&lt;P&gt;looks like a real-time search of some sort&lt;BR /&gt;
rt stands for real-time scheduler is the component that schedules the searches&lt;BR /&gt;
what is stripa?&lt;BR /&gt;
make sure to stop and disable all real-time search&lt;/P&gt;</description>
    <pubDate>Wed, 18 Sep 2019 01:05:24 GMT</pubDate>
    <dc:creator>adonio</dc:creator>
    <dc:date>2019-09-18T01:05:24Z</dc:date>
    <item>
      <title>Search killing _audit</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Search-killing-audit/m-p/483320#M4006</link>
      <description>&lt;P&gt;Our _audit file keeps growing and growing.  We have identified what is filling it up but cannot figure out what is causing it.&lt;/P&gt;

&lt;P&gt;The user is stripa.  If I search index=_audit stripa, I find 100's of thousands of events over a 15 minute period that look like this...&lt;/P&gt;

&lt;P&gt;9/17/19&lt;BR /&gt;
12:53:09.523 PM &lt;BR /&gt;
Audit:[timestamp=09-17-2019 13:53:09.523, user=splunk-system-user, action=search, info=terminate, search_id='rt_scheduler_&lt;EM&gt;stripa&lt;/EM&gt;&lt;EM&gt;search&lt;/EM&gt;_RMD55e845684aa67ede1_at_1558279620_18914'][n/a]&lt;BR /&gt;
source = audittrailsourcetype = audittrail&lt;BR /&gt;
9/17/19&lt;BR /&gt;
12:53:09.523 PM &lt;BR /&gt;
Audit:[timestamp=09-17-2019 13:53:09.523, user=splunk-system-user, action=search, info=cancel, search_id='rt_scheduler_&lt;EM&gt;stripa&lt;/EM&gt;&lt;EM&gt;search&lt;/EM&gt;_RMD55e845684aa67ede1_at_1558279620_18914'][n/a]&lt;BR /&gt;
source = audittrailsourcetype = audittrail&lt;BR /&gt;
9/17/19&lt;BR /&gt;
12:53:09.523 PM &lt;BR /&gt;
Audit:[timestamp=09-17-2019 13:53:09.523, user=splunk-system-user, action=search, info=terminate, search_id='rt_scheduler_&lt;EM&gt;stripa&lt;/EM&gt;&lt;EM&gt;search&lt;/EM&gt;_RMD52dc925e4d0d65765_at_1565488020_78337'][n/a]&lt;BR /&gt;
source = audittrailsourcetype = audittrail&lt;BR /&gt;
9/17/19&lt;BR /&gt;
12:53:09.523 PM &lt;BR /&gt;
Audit:[timestamp=09-17-2019 13:53:09.523, user=splunk-system-user, action=search, info=cancel, search_id='rt_scheduler_&lt;EM&gt;stripa&lt;/EM&gt;&lt;EM&gt;search&lt;/EM&gt;_RMD52dc925e4d0d65765_at_1565488020_78337'][n/a]&lt;BR /&gt;
source = audittrailsourcetype = audittrail&lt;BR /&gt;
9/17/19&lt;BR /&gt;
12:53:09.522 PM &lt;BR /&gt;
Audit:[timestamp=09-17-2019 13:53:09.522, user=splunk-system-user, action=search, info=terminate, search_id='rt_scheduler_&lt;EM&gt;stripa&lt;/EM&gt;&lt;EM&gt;search&lt;/EM&gt;_RMD52dc925e4d0d65765_at_1559222520_46294'][n/a]&lt;BR /&gt;
source = audittrailsourcetype = audittrail&lt;/P&gt;

&lt;P&gt;We only found two items under "Settings -&amp;gt; All Configurations" and these were unrelated reports, but we disabled them nonetheless.&lt;/P&gt;

&lt;P&gt;How can I get to the bottom of what is causing this.  I'm stumped.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 02:13:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Search-killing-audit/m-p/483320#M4006</guid>
      <dc:creator>tsheets13</dc:creator>
      <dc:date>2020-09-30T02:13:03Z</dc:date>
    </item>
    <item>
      <title>Re: Search killing _audit</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Search-killing-audit/m-p/483321#M4007</link>
      <description>&lt;P&gt;looks like a real-time search of some sort&lt;BR /&gt;
rt stands for real-time scheduler is the component that schedules the searches&lt;BR /&gt;
what is stripa?&lt;BR /&gt;
make sure to stop and disable all real-time search&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2019 01:05:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Search-killing-audit/m-p/483321#M4007</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2019-09-18T01:05:24Z</dc:date>
    </item>
    <item>
      <title>Re: Search killing _audit</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Search-killing-audit/m-p/483322#M4008</link>
      <description>&lt;P&gt;stripa is a user.&lt;/P&gt;

&lt;P&gt;How can I determine where this realtime search is running?  There are no searches or reports owned by that user that aren't disabled.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2019 11:54:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Search-killing-audit/m-p/483322#M4008</guid>
      <dc:creator>tsheets13</dc:creator>
      <dc:date>2019-09-18T11:54:26Z</dc:date>
    </item>
    <item>
      <title>Re: Search killing _audit</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Search-killing-audit/m-p/483323#M4009</link>
      <description>&lt;P&gt;apparently there are ... &lt;BR /&gt;
try this:&lt;BR /&gt;
&lt;CODE&gt;| rest /services/search/jobs | search eventSorting=realtime&lt;/CODE&gt;&lt;BR /&gt;
find the user and teach her / him&lt;BR /&gt;
if you have distributed / clustered environment, maybe that search runs on another search head or even worse, directly on a single indexer.&lt;BR /&gt;
regardless, i will highly recommend to disable real-time searches across all environment&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.1/Search/Restrictrealtimesearch"&gt;https://docs.splunk.com/Documentation/Splunk/7.3.1/Search/Restrictrealtimesearch&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2019 12:03:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Search-killing-audit/m-p/483323#M4009</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2019-09-18T12:03:47Z</dc:date>
    </item>
    <item>
      <title>Re: Search killing _audit</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Search-killing-audit/m-p/483324#M4010</link>
      <description>&lt;P&gt;In this case it's our dev enviroment.  One search head and one indexer.&lt;/P&gt;

&lt;P&gt;That search provides no results.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2019 12:09:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Search-killing-audit/m-p/483324#M4010</guid>
      <dc:creator>tsheets13</dc:creator>
      <dc:date>2019-09-18T12:09:41Z</dc:date>
    </item>
    <item>
      <title>Re: Search killing _audit</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Search-killing-audit/m-p/483325#M4011</link>
      <description>&lt;P&gt;in the _audit data, look for the &lt;CODE&gt;host&lt;/CODE&gt; field value and &lt;CODE&gt;splunk_server&lt;/CODE&gt; field value&lt;BR /&gt;
this user might saves their search in private mode ...&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 02:17:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Search-killing-audit/m-p/483325#M4011</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2020-09-30T02:17:32Z</dc:date>
    </item>
    <item>
      <title>Re: Search killing _audit</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Search-killing-audit/m-p/483326#M4012</link>
      <description>&lt;P&gt;host is the hostname of the search head&lt;/P&gt;

&lt;P&gt;splunk_server is the DNS name of the search head&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2019 16:16:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Search-killing-audit/m-p/483326#M4012</guid>
      <dc:creator>tsheets13</dc:creator>
      <dc:date>2019-09-18T16:16:18Z</dc:date>
    </item>
  </channel>
</rss>

