Installation

How can I display the subsearch_scheduler in _internal?

Alan
New Member

How can I display the subsearch_scheduler.

index=_internal
[ inputlookup splunk-servers
| search splunk-component="Search Head"
| fields host] source=/opt/ovz/splunk/var/log/splunk/scheduler.log [search index=_internal
[ inputlookup splunk-servers
| search splunk-component="Search Head"
| fields host] log_level=ERROR component=SearchMessages sid=subsearch_scheduler*
| table sid
| dedup sid]
| stats count values(savedsearch_name) dc(savedsearch_name) by user
| sort - count

Labels (2)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

What problem are you trying to solve?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...