I have a lot of scheduled searches in one of our shared accounts.
How do you analyze which are the top aggressive searches with regards to frequency (rt, 5 min etc.) or resources (not restricted to specific sourcetype, host etc.)
My intention is to clear out some intensive alerts/reports.
This app was built to identify searches with high resource utilization (among other things): https://splunkbase.splunk.com/app/2678/
Start with the above search. You can then look how frequent a search is running by doing time chart on the savedsearch_name.
run_time, result_count are few other parameters you can look at to figure out expensive searches.