Getting Data In

How to set workload management rules?

saleshai
Loves-to-Learn Lots

Hi,

I'm trying to set 2 rules in my workload management pool -

search_type=adhoc AND runtime>1m -> Move search to alternate Pool: limited_perf

&

search_type=adhoc AND runtime>10m -> Abort search

The second condition is not getting picked & I still see many long running searches under the Expensive search dashboard. I thought it is a problem with the way these conditions are defined, so I tried changing it to -

search_type=adhoc AND (runtime>1m AND runtime<=10m) - But its throwing error

ERROR: Workload rule "move_longrunning_to_limited_pool" validation failed with error=invalid predicate format 'runtime<=10m'

Where am I going wrong?

Labels (1)
0 Karma

caiosalonso
Path Finder

Hi,

Just checking, if you use just runtime<10m instead of runtime<=10, as below, you get the same invalid predicate format error?

search_type=adhoc AND (runtime>1m AND runtime<10m) 

Also, only the second rule that should abort the search is not working? The first one is working as expected?

 

0 Karma

saleshai
Loves-to-Learn Lots

Hi, So it did not work even with taking the = sign out.

I figured, the workload rules execute as per sequence. The order of the rules is important. Rules are evaluated in order from top to bottom. When I changed the sequence of both rules, it worked correctly -

Rule 1 - search_type=adhoc AND runtime>10m

Rule 2 - search_type=adhoc AND runtime>1m

(I removed the extra conditions & simplified the query)

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...