Monitoring Splunk

what is limit of cronjob schedule ?

gurveer_singh88
New Member

I have one requirement where I have to schedule more than 1000 cronjobs on different time period and system will execute individual cronjob in each 10 minutes.

I just want to know, is there any limit in in Splunk Enterprise to save a particular number of cronjobs like 100, 200 or something?

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

There is no limit to the number of jobs that can be scheduled. There is, however, a limit to the number of jobs that can be executed. Each cron job requires a CPU core to run. Since you have 1000 jobs running every 10 minutes, that's roughly 100 jobs per minute. That means you need at least 100 cores in your Splunk server. Fewer cores means some jobs will have to wait for others to complete and may be skipped.

---
If this reply helps you, Karma would be appreciated.
0 Karma

Yasaswy
Contributor

hi,

I think this might have more to do with your system resources than with Splunk. Typically each of your saved search executing at the same time will consume a CPU core. Once your CPUs are maxed your searches will queue up and impact the performance.

0 Karma

gurveer_singh88
New Member

Very true Yasaswy, It will impact system performance. Definitely it requires good amount of computing power. All i want to know, will splunk allow me to add these many number of jobs ?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes, Splunk will allow you to add that many jobs.

---
If this reply helps you, Karma would be appreciated.
0 Karma

gurveer_singh88
New Member

Thanks Rich and Yasaswy for reply. I will be more careful while sizing.

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...