Splunk IT Service Intelligence

Efficient scheduling of the correlation searches in Splunk ITSI to avoid skipping of concurrent running jobs.

ManjunathNargun
New Member

Hi,

How to efficiently schedule the correlation searches in Splunk ITSI to avoid skipping of concurrent running jobs.

We can see the below message in skipped searches.

ManjunathNargun_0-1693583634440.png

 

Thanks!

 

 

Labels (1)
0 Karma

srauhala_splunk
Splunk Employee
Splunk Employee

Hi @ManjunathNargun 

 

The key is to have the searches execute before their next schedule time. If you run a search every 5 min it should not take more then 5 min to complete. 

See https://docs.splunk.com/Documentation/Splunk/9.1.1/Search/Writebettersearches on how to write efficient searches. 

Other options are to reduce search frequency or add more search resources (search head and indexer CPU resources)

/Seb  

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...