All Apps and Add-ons

How to search for the most expensive searches

dolfantimmy
Path Finder

I have been asked to create a search that will provide the most costly searches that are run. I know from reading other posts that I can get this from the SOS app. But I haven't found the search that provides this information. I also need to add it to a dashboard.

Thanks in advance for the assistance.

hexx
Splunk Employee
Splunk Employee

It really depends what you consider to be an "expensive" search!

Is a search that uses several gigabytes of physical memory expensive? If yes, you might want to check the "Top 20 memory-consuming searches" panel in the "CPU/Memory Resource Usage" view to identify such searches.

Is a search that runs for several hours expensive? If yes, you should probably take a look at the "Search Usage Patterns" view.

Finally, for a higher-level view of your search workload, I would recommend to start with the "Search Activity" view.

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...