Installation

How can I display the subsearch_scheduler in _internal?

Alan
New Member

How can I display the subsearch_scheduler.

index=_internal
[ inputlookup splunk-servers
| search splunk-component="Search Head"
| fields host] source=/opt/ovz/splunk/var/log/splunk/scheduler.log [search index=_internal
[ inputlookup splunk-servers
| search splunk-component="Search Head"
| fields host] log_level=ERROR component=SearchMessages sid=subsearch_scheduler*
| table sid
| dedup sid]
| stats count values(savedsearch_name) dc(savedsearch_name) by user
| sort - count

Labels (2)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

What problem are you trying to solve?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...