How do we identify which splunk search is consuming more memory on the splunk indexers ?
The monitoring console will work for this case as per MuS's link, Alerts For Splunk Admins has a dashboard called Troubleshooting indexer CPU, it can also be used to look at searches by memory through the introspection index.
Or you can just re-use the queries from the dashboard to view the data you want from the introspection index.
Hi splunker969,
read the docs about the management console http://docs.splunk.com/Documentation/Splunk/latest/DMC/DMCoverview and most specific about the search usage statistics dashboard http://docs.splunk.com/Documentation/Splunk/latest/DMC/Searchusagestatistics
Hope that helps ...
cheers, MuS