Monitoring Splunk

Saved Search Pre-Flight Check

sambosplunk
Engager

Is there a way to look at a Splunk Search and check it for common issues that might cause the search to run long in advance of setting up the Search and seeing how it performs?

The process at http://wiki.splunk.com/Deploy:SearchPerformance outlines how to troubleshoot an existing bad search, but I am looking for an more automated way to call out issues prior to scheduling on the server. Looking to empower users to create their own searches, but need to ensure that they have not built the search in a way that won't scale.

Has anyone automated this check, and if so, how? If not, are there a more detailed set of steps other than the above that we could use as a starting point for a preflight check?

Any help is much appreciated. Thanks!

dart
Splunk Employee
Splunk Employee

The Sanity Checking App should help you out here. It uses Splunk's REST API to get information about Splunk saved searches.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...