<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SHC Concurrency Search control in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/SHC-Concurrency-Search-control/m-p/761970#M243545</link>
    <description>&lt;P&gt;Kindly, from the below screenshots, we can find that there are some RT scheduled search are enabled by default by splunk itself, and use the indexed real-time, so can we create some real-time scheduled search so we can accomodate the RT pool?&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="003 - RT - Scheduled Search.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/42295iA590F065B0BE06C4/image-size/large?v=v2&amp;amp;px=999" role="button" title="003 - RT - Scheduled Search.png" alt="003 - RT - Scheduled Search.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 27 Jun 2026 13:18:22 GMT</pubDate>
    <dc:creator>0xAli</dc:creator>
    <dc:date>2026-06-27T13:18:22Z</dc:date>
    <item>
      <title>SHC Concurrency Search control</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SHC-Concurrency-Search-control/m-p/761858#M243535</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;I hope all is well.&lt;BR /&gt;&lt;BR /&gt;I am writting to ensure i am getting the correct picture on the SHC search:&lt;BR /&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;Assumption:&amp;nbsp;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;3x search head with CPU: 32 cores.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;max search per cpu = 2&lt;/FONT&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;SPAN&gt;max_hist_searches =&amp;nbsp; max_searches_per_cpu x number_of_cpus + base_max_searches &lt;/SPAN&gt;&lt;SPAN&gt;(our environment is 70 per node)&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Max Scheduled Search = 50% * max_hist_searches &amp;nbsp;= 35&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Max Summarization&amp;nbsp; = 50% * Scheduled Search =17&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Max Ad hoc guaranteed = &lt;STRONG&gt;35 &lt;/STRONG&gt;Remaining — always reserved for analysts&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Only SCHEDULED searches are coordinated by the captain across nodes&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Reference:&lt;/SPAN&gt;&lt;BR /&gt;&lt;A title="https://help.splunk.com/en/splunk-enterprise/administer/distributed-search/10.4/manage-search-head-clustering/control-search-concurrency-on-search-head-clusters" href="https://help.splunk.com/en/splunk-enterprise/administer/distributed-search/10.4/manage-search-head-clustering/control-search-concurrency-on-search-head-clusters" target="_blank" rel="noreferrer noopener"&gt;&lt;SPAN&gt;https://help.splunk.com/en/splunk-enterprise/administer/distributed-search/10.4/manage-search-head-…&lt;/SPAN&gt;&lt;/A&gt;&lt;BR /&gt;&lt;A title="https://community.splunk.com/t5/reporting/how-to-calculate-splunk-search-concurrency-limit-for-historical/td-p/116228?_gl=1*u2mtw5*_gcl_au*ntkwmdu5mtuzlje3nzc4mtiwmda.*fpau*ntkwmdu5mtuzlje3nzc4mtiwmda.*_ga*mzawmdazmtg2lje3nzawmzi5odg.*_ga_5epm2p39fv*cze3odiymju2nzikbze1nsrnmcr0mtc4mjiynty3mirqnjakbdakadeyodu5mti2nzm.*_fplc*twzqttu1cnbotfz5wjjjdddtrddmdghjcm9twxpkvexrmwu1mvhgjtjcmzv1me83nmx0mvq5d09woevlcejuck5pttjwvdfzdzzdsthkvfh1aup2teryr2dimwxoc0y3emzoalviuu5jvwpkqwdxwktzvghoaddjjtjgt1pouzltusuzrcuzra.." href="https://community.splunk.com/t5/Reporting/How-to-calculate-Splunk-search-concurrency-limit-for-historical/td-p/116228?_gl=1*u2mtw5*_gcl_au*NTkwMDU5MTUzLjE3Nzc4MTIwMDA.*FPAU*NTkwMDU5MTUzLjE3Nzc4MTIwMDA.*_ga*MzAwMDAzMTg2LjE3NzAwMzI5ODg.*_ga_5EPM2P39FV*czE3ODIyMjU2NzIkbzE1NSRnMCR0MTc4MjIyNTY3MiRqNjAkbDAkaDEyODU5MTI2NzM.*_fplc*TWZqTTU1cnBOTFZ5WjJJdDdtRDdMdGhjcm9tWXpkVExrMWU1MVhGJTJCMzV1ME83Nmx0MVQ5d09wOEVlcEJUck5pTTJwVDFZdzZDSThKVFh1aUp2TERYR2diMWxOc0Y3emZoalVIUU5JVWpKQWdxWktzVGhOaDdjJTJGT1poUzltUSUzRCUzRA.." target="_blank" rel="noreferrer noopener"&gt;&lt;SPAN&gt;https://community.splunk.com/t5/Reporting/How-to-calculate-Splunk-search-concurrency-limit-for-hist…&lt;/SPAN&gt;&lt;/A&gt;&lt;BR /&gt;&lt;A title="https://www.splunk.com/en_us/blog/tips-and-tricks/are-you-skipping-please-read.html" href="https://www.splunk.com/en_us/blog/tips-and-tricks/are-you-skipping-please-read.html" target="_blank" rel="noreferrer noopener"&gt;&lt;SPAN&gt;Are You Skipping? Please Read! | Splunk&lt;/SPAN&gt;&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;P&gt;&lt;STRONG&gt;For Real-time searches:&lt;BR /&gt;&lt;SPAN&gt;max_rt_searches = max_rt_search_multiplier x max_hist_searches&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Max real-time searches = 1 * 70 = 70 ( our environment per node).&lt;/LI&gt;&lt;LI&gt;Max real-time scheduled searches = 50% x 70 = 35&lt;/LI&gt;&lt;LI&gt;Max Ad hoc guaranteed = &lt;STRONG&gt;35 &lt;/STRONG&gt;Remaining — always reserved for analysts&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;As per the above, we can conclude the below per each node:&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Historical ad hoc&lt;/STRONG&gt; → shared 70 pool (User manuall search past data)&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Historical scheduled&lt;/STRONG&gt; → 35 (50% of 70)&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Summarization&lt;/STRONG&gt; → 17 (50% of 35) (Datamodel)&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;RT scheduled&lt;/STRONG&gt; → 35 (separate RT pool, independent)&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;RT ad hoc&lt;/STRONG&gt; → 35 (RT guaranteed, reserved for analysts) (User manually search for RT live stream data)&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Scheduled ad hoc&lt;/STRONG&gt; → does not exist&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2026 23:39:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SHC-Concurrency-Search-control/m-p/761858#M243535</guid>
      <dc:creator>0xAli</dc:creator>
      <dc:date>2026-06-25T23:39:18Z</dc:date>
    </item>
    <item>
      <title>Re: SHC Concurrency Search control</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SHC-Concurrency-Search-control/m-p/761868#M243536</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/314750"&gt;@0xAli&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;your settings seem to be correct, the only way to proceed is to analyze the load on your SHs using the Monitoring Consle, in this way you can see the health status of your system and eventually put some tuning action, e.g.:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;check the scheduling of the scheduled searches,&lt;/LI&gt;&lt;LI&gt;avoid to use real-time searches and transforms them in scheduled searches,&lt;/LI&gt;&lt;LI&gt;optimize your custom searches,&lt;/LI&gt;&lt;LI&gt;check the performances of the Data Models,&lt;/LI&gt;&lt;LI&gt;etc...&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2026 06:29:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SHC-Concurrency-Search-control/m-p/761868#M243536</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2026-06-24T06:29:45Z</dc:date>
    </item>
    <item>
      <title>Re: SHC Concurrency Search control</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SHC-Concurrency-Search-control/m-p/761871#M243537</link>
      <description>&lt;P&gt;Thanks for your support,&amp;nbsp; it's really appreciated!&lt;BR /&gt;&lt;BR /&gt;Could you please clarify more on that point:&lt;BR /&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;"avoid to use real-time searches and transforms them in scheduled searches,"&lt;BR /&gt;&lt;BR /&gt;&lt;/FONT&gt;&lt;FONT color="#000000"&gt;As from the calculated values, we have two separate pool, one for the historical scheduled search(35 - Summarization), and one for the RT-scheduled search(35), so the capacity of the RT will not affect the historical, and it's higher than historical (35 = Summarization + Historical scheduled search).&lt;BR /&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;real-time searches meand ES detection + RT mode ?&lt;BR /&gt;&amp;nbsp;scheduled searches means ES detection + Continous mode ?&lt;/FONT&gt;&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2026 10:11:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SHC-Concurrency-Search-control/m-p/761871#M243537</guid>
      <dc:creator>0xAli</dc:creator>
      <dc:date>2026-06-24T10:11:42Z</dc:date>
    </item>
    <item>
      <title>Re: SHC Concurrency Search control</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SHC-Concurrency-Search-control/m-p/761878#M243539</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/314750"&gt;@0xAli&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;about first question:&lt;/P&gt;&lt;P&gt;in Splunk a search takes a CPU (more if you have also subsearches in the main search) until it will finish, so a RT search takes one or more CPUs for always, it's better to schedule a search so it will release the CPUs when finised.&lt;/P&gt;&lt;P&gt;About second question:&lt;/P&gt;&lt;P&gt;No RT depends on how you configured your detections: scheduled or RT, as I said if you can avoid RT, otherwise give more resources (CPUs to your Indexers and Search Heads)!&lt;/P&gt;&lt;P&gt;On Splunk Cloud RT searches are usually blocked for all not admin users!&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2026 13:48:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SHC-Concurrency-Search-control/m-p/761878#M243539</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2026-06-24T13:48:19Z</dc:date>
    </item>
    <item>
      <title>Re: SHC Concurrency Search control</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SHC-Concurrency-Search-control/m-p/761882#M243540</link>
      <description>&lt;P&gt;Now, i got your point, the confuse comes from the hint under the RT/scheduled mode&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RT-Scheduled.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/42263i8ABB7E5A3F31CE72/image-size/large?v=v2&amp;amp;px=999" role="button" title="RT-Scheduled.png" alt="RT-Scheduled.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2026 14:29:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SHC-Concurrency-Search-control/m-p/761882#M243540</guid>
      <dc:creator>0xAli</dc:creator>
      <dc:date>2026-06-24T14:29:04Z</dc:date>
    </item>
    <item>
      <title>Re: SHC Concurrency Search control</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SHC-Concurrency-Search-control/m-p/761884#M243541</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/314750"&gt;@0xAli&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;is is clear for you or do you need other information?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2026 15:48:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SHC-Concurrency-Search-control/m-p/761884#M243541</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2026-06-24T15:48:22Z</dc:date>
    </item>
    <item>
      <title>Re: SHC Concurrency Search control</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SHC-Concurrency-Search-control/m-p/761945#M243542</link>
      <description>&lt;P&gt;Yes, the terminology here can be somewhat confusing. Splunk uses the term "real-time" in two different contexts when it comes to searching.&amp;nbsp;&lt;/P&gt;&lt;P&gt;One thing is a real time search. It is a search which is done not against already indexed data but on the incoming data as it is ingested by Splunk. This type of search allocates one cpu on a search head running the search for the whole time the search is running and one cpu on each participating indexer. The other type of a search is a historical search which runs on data returned by indexers from the buckets residing on disk - already indexed data.&lt;/P&gt;&lt;P&gt;Another thing is the realtime schedule mode. This means that a run of a scheduled search will be attempted at the scheduled time but if there are no free search slots, Splunk will delay it for some time (if configuration of the search allows it) but if it still cannot find free slot to run it the search run will get skipped. The other scheduling mode is continuous which means that Splunk will try to run the search for a given time slot indefinitely until it finally can do so (I suppose there are some technical limits to that but that's the general idea). The caveat is that continuously scheduled searches have lower priority within the scheduler.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2026 22:08:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SHC-Concurrency-Search-control/m-p/761945#M243542</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2026-06-25T22:08:01Z</dc:date>
    </item>
    <item>
      <title>Re: SHC Concurrency Search control</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SHC-Concurrency-Search-control/m-p/761947#M243543</link>
      <description>&lt;P&gt;Thank you!&lt;BR /&gt;&lt;BR /&gt;Let me leave what i have got from the truly insighful discussion with you all below:&lt;BR /&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;1.&amp;nbsp;Schedule Mode (Continous or real-time)&lt;/FONT&gt; doesn't determine the type of the&amp;nbsp;Scheduled Search(RTScheduled Search OR Historical&amp;nbsp;Scheduled Search ), it just determine the behaviour at the status: unavailable search slots, and how the&amp;nbsp;Scheduled Search will run weather it will be skipped or&amp;nbsp;DEFERRED?&lt;BR /&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;then historical scheduled Search can be operate at the&amp;nbsp;Continuous mode ot the&amp;nbsp;Real-time mode ?&lt;BR /&gt;A Real-time scheduled Search always uses Real-time scheduling by nature?&lt;BR /&gt;&lt;BR /&gt;&lt;/FONT&gt;If am i correct - as per the above - kindly, give me example on the&amp;nbsp;&lt;FONT color="#FF0000"&gt;Real-time scheduled Search and&amp;nbsp;historical scheduled Search (when can i say it's RT-scheduled Search or historical&amp;nbsp;scheduled Search)?&lt;/FONT&gt;&lt;/P&gt;&lt;H1&gt;&lt;FONT size="4"&gt;All event-based detection is historical scheduled search?&lt;BR /&gt;&lt;BR /&gt;Thank in advance!&lt;/FONT&gt;&lt;/H1&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2026 23:37:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SHC-Concurrency-Search-control/m-p/761947#M243543</guid>
      <dc:creator>0xAli</dc:creator>
      <dc:date>2026-06-25T23:37:31Z</dc:date>
    </item>
    <item>
      <title>Re: SHC Concurrency Search control</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SHC-Concurrency-Search-control/m-p/761952#M243544</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/314750"&gt;@0xAli&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;about the first assumption, it isn't correct:&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;Schedule Mode (Continous or real-time)&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;determine the type of the&amp;nbsp;Scheduled Search(RTScheduled Search OR Historical&amp;nbsp;Scheduled Search)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;historical scheduled Search can be operate at the&amp;nbsp;Continuous mode ot the&amp;nbsp;Real-time mode ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;historical scheduled Search are in Continuous Mode, not in RT Mode, what's the sense of a RT historical search?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;A Real-time scheduled Search always uses Real-time scheduling by nature?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;yes&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2026 06:18:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SHC-Concurrency-Search-control/m-p/761952#M243544</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2026-06-26T06:18:14Z</dc:date>
    </item>
    <item>
      <title>Re: SHC Concurrency Search control</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SHC-Concurrency-Search-control/m-p/761970#M243545</link>
      <description>&lt;P&gt;Kindly, from the below screenshots, we can find that there are some RT scheduled search are enabled by default by splunk itself, and use the indexed real-time, so can we create some real-time scheduled search so we can accomodate the RT pool?&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="003 - RT - Scheduled Search.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/42295iA590F065B0BE06C4/image-size/large?v=v2&amp;amp;px=999" role="button" title="003 - RT - Scheduled Search.png" alt="003 - RT - Scheduled Search.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 27 Jun 2026 13:18:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SHC-Concurrency-Search-control/m-p/761970#M243545</guid>
      <dc:creator>0xAli</dc:creator>
      <dc:date>2026-06-27T13:18:22Z</dc:date>
    </item>
    <item>
      <title>Re: SHC Concurrency Search control</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SHC-Concurrency-Search-control/m-p/761971#M243546</link>
      <description>&lt;P&gt;No.&amp;nbsp; If you turn on indexed real-time searches, it changes slightly the way real-time searches work. But it's still about real-time search, not about real-time schedule. (yes, I know it's confusing, I've already said so ;-))&lt;/P&gt;</description>
      <pubDate>Sat, 27 Jun 2026 13:24:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SHC-Concurrency-Search-control/m-p/761971#M243546</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2026-06-27T13:24:56Z</dc:date>
    </item>
    <item>
      <title>Re: SHC Concurrency Search control</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SHC-Concurrency-Search-control/m-p/761972#M243547</link>
      <description>&lt;P&gt;Thank you, really appreciated!&lt;/P&gt;</description>
      <pubDate>Sat, 27 Jun 2026 13:26:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SHC-Concurrency-Search-control/m-p/761972#M243547</guid>
      <dc:creator>0xAli</dc:creator>
      <dc:date>2026-06-27T13:26:46Z</dc:date>
    </item>
    <item>
      <title>Re: SHC Concurrency Search control</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SHC-Concurrency-Search-control/m-p/761980#M243551</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/314750"&gt;@0xAli&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;let us know if we can help you more, or, please, accept one answer for the other people of Community.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated by all the contributors &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2026 07:02:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SHC-Concurrency-Search-control/m-p/761980#M243551</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2026-06-29T07:02:53Z</dc:date>
    </item>
    <item>
      <title>Re: SHC Concurrency Search control</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SHC-Concurrency-Search-control/m-p/762005#M243555</link>
      <description>&lt;P&gt;Guys,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please read these articles carefully:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;A title="https://help.splunk.com/en/splunk-enterprise/search/search-manual/9.3/search-and-report-in-real-time/about-real-time-searches-and-reports" href="https://help.splunk.com/en/splunk-enterprise/search/search-manual/9.3/search-and-report-in-real-time/about-real-time-searches-and-reports" rel="noreferrer noopener" target="_blank"&gt;https://help.splunk.com/en/splunk-enterprise/search/search-manual/9.3/search-and-report-in-real-tim…&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A title="https://help.splunk.com/en/splunk-enterprise/administer/distributed-search/9.4/manage-search-head-clustering/control-search-concurrency-on-search-head-clusters" href="https://help.splunk.com/en/splunk-enterprise/administer/distributed-search/9.4/manage-search-head-clustering/control-search-concurrency-on-search-head-clusters" rel="noreferrer noopener" target="_blank"&gt;https://help.splunk.com/en/splunk-enterprise/administer/distributed-search/9.4/manage-search-head-c…&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A title="https://splunk.my.site.com/customer/s/article/real-time-scheduling-vs-continuous-scheduling" href="https://splunk.my.site.com/customer/s/article/Real-time-scheduling-vs-Continuous-scheduling" rel="noreferrer noopener" target="_blank"&gt;https://splunk.my.site.com/customer/s/article/Real-time-scheduling-vs-Continuous-scheduling&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Summary:&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;the type of the scheduled search:&lt;/SPAN&gt;&lt;BR /&gt;The Earliest and Latest time attributes are determine the type of the scheduled search weather it's Real-Time OR Historical&lt;BR /&gt;&lt;BR /&gt;Rule:&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Search for the past data = Historical &amp;nbsp;&lt;A title="mailto:-5m@m" href="mailto:-5m@m" rel="noreferrer noopener" target="_blank"&gt;&lt;SPAN&gt;-5m@m&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; to -65m@m&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Search for the Live stream = Real-Time &lt;SPAN&gt;rt-5m to rt-65m&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;the scheduling mode:&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;determine what is the behavior of the scheduled search when no available search slots, if it will be skipped or deferred.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Rule:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Continuous mode: Deferred&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Real-Time mode: Skipped&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Tue, 30 Jun 2026 09:28:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SHC-Concurrency-Search-control/m-p/762005#M243555</guid>
      <dc:creator>0xAli</dc:creator>
      <dc:date>2026-06-30T09:28:31Z</dc:date>
    </item>
  </channel>
</rss>

