How can I display the subsearch_scheduler.
index=_internal
[ inputlookup splunk-servers
| search splunk-component="Search Head"
| fields host] source=/opt/ovz/splunk/var/log/splunk/scheduler.log [search index=_internal
[ inputlookup splunk-servers
| search splunk-component="Search Head"
| fields host] log_level=ERROR component=SearchMessages sid=subsearch_scheduler*
| table sid
| dedup sid]
| stats count values(savedsearch_name) dc(savedsearch_name) by user
| sort - count
What problem are you trying to solve?