Using Splunk ES 5.3.1, I have a saved search that reached the 25GB limit (srchDiskQuota) before being finalized. This ran two days in a row and ended up filling my dispatch directory. In total it was searching over 65 billion events over the 30 day time period in the Web datamodel.
Looking through the jobs I was able to identify the search and disabled it from running further. However, I don't know where this search is used in ES and where the results are used. I'd like to determine that so I know what will be missing and where by disabling this search. The only information I have found is that it is used in the Machine Learning Tool Kit but I don't have MLTK installed in ES nor is it an applicable version.
Name: Web - Web Event Count By Src By HTTP Method Per 1d - Context Gen