Hi All, Can anyone guide me, on how to find the saved search name from the below saved search names.
index="_internal" source="*scheduler.log" savedsplunker | stats count BY user, savedsearch_name, host,status
Based on the search result, I found skipped status are getting generated from two splunk instance node
1) Search head cluster master
2) Deployment server
User: Admin & nobody
But unable to get the exact saved search name from the list, I could see the below name under saved search column
_ACCELERATE_C090FDA2-105E-4875-A110-3F13FF986151_SA-critical_security_controls_admin_2472f801659441b4_ACCELERATE
ACCELERATE_D4D707D0-38F3-4F47-A1AA-9DD305E110D0_DA-deployment_monitor_nobody_1a56f43bf8d5bf20_ACCELERATE
ACCELERATE_D4D707D0-38F3-4F47-A1AA-9DD305E110D0_search_nobody_365ca83246f2cca8_ACCELERATE
Note: Actually we are getting this message """The maximum number of concurrent auto-summarization searches on this instance has been reached" it is occurring due to currently running summarization searches have not completed and the scheduler cannot start the next summarization search. Due to which we could see some of the scheduled searches are skipped without running.
so we wanted to list out all auto-summarization searches from search head cluster and we may be able to remove some of that aren't needed before making a change that has the potential to greatly impact performance.
we are getting the list of accelerated saved search name as "ACCELERATE_D4D707D0-38F3-4F47-A1AA-9DD305E110D0_search_nobody_365ca83246f2cca8_ACCELERATE: so unable to find the exact name of it.
Kindly guide me how to get this fixed.
thanks in advance.