- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
deodeshm
Explorer
06-20-2023
09:41 PM
Where can I see ES content searches performance in terms of avg. time taken to run a particular correlation rule or saved search?
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
06-21-2023
05:12 AM
You should be able to get that information from the scheduler log.
index=_internal source=*scheduler.log run_time=*
| stats avg(run_time) by savedsearch_name
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
06-21-2023
05:12 AM
You should be able to get that information from the scheduler log.
index=_internal source=*scheduler.log run_time=*
| stats avg(run_time) by savedsearch_name
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
