Reporting

How to find the exact saved search names in splunk ?

Hemnaath
Motivator

Hi All, Can anyone guide me, on how to find the saved search name from the below saved search names.

index="_internal" source="*scheduler.log" savedsplunker | stats count BY user, savedsearch_name, host,status

Based on the search result, I found skipped status are getting generated from two splunk instance node

1) Search head cluster master
2) Deployment server

User: Admin & nobody

But unable to get the exact saved search name from the list, I could see the below name under saved search column

_ACCELERATE_C090FDA2-105E-4875-A110-3F13FF986151_SA-critical_security_controls_admin_2472f801659441b4_ACCELERATE

ACCELERATE_D4D707D0-38F3-4F47-A1AA-9DD305E110D0_DA-deployment_monitor_nobody_1a56f43bf8d5bf20_ACCELERATE

ACCELERATE_D4D707D0-38F3-4F47-A1AA-9DD305E110D0_search_nobody_365ca83246f2cca8_ACCELERATE

Note: Actually we are getting this message """The maximum number of concurrent auto-summarization searches on this instance has been reached" it is occurring due to currently running summarization searches have not completed and the scheduler cannot start the next summarization search. Due to which we could see some of the scheduled searches are skipped without running.

so we wanted to list out all auto-summarization searches from search head cluster and we may be able to remove some of that aren't needed before making a change that has the potential to greatly impact performance.

we are getting the list of accelerated saved search name as "ACCELERATE_D4D707D0-38F3-4F47-A1AA-9DD305E110D0_search_nobody_365ca83246f2cca8_ACCELERATE: so unable to find the exact name of it.

Kindly guide me how to get this fixed.

thanks in advance.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...