Getting Data In

How to set workload management rules?

saleshai
Loves-to-Learn Lots

Hi,

I'm trying to set 2 rules in my workload management pool -

search_type=adhoc AND runtime>1m -> Move search to alternate Pool: limited_perf

&

search_type=adhoc AND runtime>10m -> Abort search

The second condition is not getting picked & I still see many long running searches under the Expensive search dashboard. I thought it is a problem with the way these conditions are defined, so I tried changing it to -

search_type=adhoc AND (runtime>1m AND runtime<=10m) - But its throwing error

ERROR: Workload rule "move_longrunning_to_limited_pool" validation failed with error=invalid predicate format 'runtime<=10m'

Where am I going wrong?

Labels (1)
0 Karma

caiosalonso
Path Finder

Hi,

Just checking, if you use just runtime<10m instead of runtime<=10, as below, you get the same invalid predicate format error?

search_type=adhoc AND (runtime>1m AND runtime<10m) 

Also, only the second rule that should abort the search is not working? The first one is working as expected?

 

0 Karma

saleshai
Loves-to-Learn Lots

Hi, So it did not work even with taking the = sign out.

I figured, the workload rules execute as per sequence. The order of the rules is important. Rules are evaluated in order from top to bottom. When I changed the sequence of both rules, it worked correctly -

Rule 1 - search_type=adhoc AND runtime>10m

Rule 2 - search_type=adhoc AND runtime>1m

(I removed the extra conditions & simplified the query)

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...