Monitoring Splunk
Highlighted

Why does this _internal log message have two similar key=value pairs and can this be changed?

Explorer

It's not really a question, but could you please change your _internal log message:

The maximum number of concurrent scheduled searches has been reached (limits: historical=2, realtime=2). historical=21, realtime=0 ready-to-run scheduled searches are pending.

I have to add a regular expression to get the interesting historical value.

0 Karma
Highlighted

Re: Why does this _internal log message have two similar key=value pairs and can this be changed?

Splunk Employee
Splunk Employee

Please feel free to submit an enhancement request via the Splunk support portal .

0 Karma
Highlighted

Re: Why does this _internal log message have two similar key=value pairs and can this be changed?

Explorer

Only if someone has the same problem. I used this regex in order to get the value from the second historical pair.

| rex field=_raw "). historical=(?\d+)"

0 Karma