All Apps and Add-ons

How to search for the most expensive searches

dolfantimmy
Path Finder

I have been asked to create a search that will provide the most costly searches that are run. I know from reading other posts that I can get this from the SOS app. But I haven't found the search that provides this information. I also need to add it to a dashboard.

Thanks in advance for the assistance.

hexx
Splunk Employee
Splunk Employee

It really depends what you consider to be an "expensive" search!

Is a search that uses several gigabytes of physical memory expensive? If yes, you might want to check the "Top 20 memory-consuming searches" panel in the "CPU/Memory Resource Usage" view to identify such searches.

Is a search that runs for several hours expensive? If yes, you should probably take a look at the "Search Usage Patterns" view.

Finally, for a higher-level view of your search workload, I would recommend to start with the "Search Activity" view.

Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...