We have X-numbers of search heads. i want to create a dashboard which will calculate searches per minute on each Splunk search head. So please help me with the search query.
maybe try this
index=_audit action="search" search="*" NOT user="splunk-system-user" savedsearch_name="" NOT search="\'|history*" NOT search="\'typeahead*" | timechart span=1m count by host
But take care about the span 1m is maybe to much and could end in "The specified span would result in too many (>50000) rows."
"The specified span would result in too many (>50000) rows."
Pls note this will exclude saved searches
You can also exculde summary searches by adding NOT search="'summarize*"
View solution in original post