All Apps and Add-ons

How to search for the most expensive searches

dolfantimmy
Path Finder

I have been asked to create a search that will provide the most costly searches that are run. I know from reading other posts that I can get this from the SOS app. But I haven't found the search that provides this information. I also need to add it to a dashboard.

Thanks in advance for the assistance.

hexx
Splunk Employee
Splunk Employee

It really depends what you consider to be an "expensive" search!

Is a search that uses several gigabytes of physical memory expensive? If yes, you might want to check the "Top 20 memory-consuming searches" panel in the "CPU/Memory Resource Usage" view to identify such searches.

Is a search that runs for several hours expensive? If yes, you should probably take a look at the "Search Usage Patterns" view.

Finally, for a higher-level view of your search workload, I would recommend to start with the "Search Activity" view.

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...