Splunk Search

Help regarding splunk queries ?

splunker969
Communicator

Hi Splunk members,

How Can I get some metrics to indicate things like search concurrency, search queue depth, cancelled/timed out searches, etc by search head and by indexer?

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi splunker969,

have you read about the monitoring console http://docs.splunk.com/Documentation/Splunk/latest/DMC/DMCoverview yet?

cheers, MuS

0 Karma

deepashri_123
Motivator

Hey@splunker969,

You can try using metrics.log for various parameters.
Eg: index=_internal source=*metrics.log group=search_concurrency "system total" OR you can also use audit logs.

Let me know if this helps!!

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...