Splunk Search

How to change the frequency of search jobs scheduled to run from configuration files to prevent 100% CPU usage?

Javo222
Path Finder

I've messed my Splunk system up a bit and some jobs or searches (I don't remember) are continuously running (every minute I think). This causes my CPU to rise to 100% a few seconds after splunkd starts. Unfortunately, I don't have time to stop them or edit them from Splunk Web.

Are the jobs stored in any config file? I would like to edit them so I can change the frequency to 24h or so.

Right now I'm stuck and can't do anything.

0 Karma
1 Solution

sjohnson_splunk
Splunk Employee
Splunk Employee

Look for a file: savedsearches.conf inside of an app/local directory: (like etc/apps/search/local)

View solution in original post

0 Karma

sjohnson_splunk
Splunk Employee
Splunk Employee

Look for a file: savedsearches.conf inside of an app/local directory: (like etc/apps/search/local)

0 Karma

Javo222
Path Finder

Thanks! Found it under C:\Program Files\Splunk\etc\users\admin\search\local

0 Karma

skoelpin
SplunkTrust
SplunkTrust

You can access all your saved searches in the Splunk web interface (The GUI).. Go to the top left where it says Activity then select Jobs and this will show all the searches that are running

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...