Splunk Search

How to identify the top aggressive scheduled searches in our environment in regards to frequency and resource utilization?

aniketb
Path Finder

I have a lot of scheduled searches in one of our shared accounts.

How do you analyze which are the top aggressive searches with regards to frequency (rt, 5 min etc.) or resources (not restricted to specific sourcetype, host etc.)

My intention is to clear out some intensive alerts/reports.

0 Karma

masonmorales
Influencer

This app was built to identify searches with high resource utilization (among other things): https://splunkbase.splunk.com/app/2678/

0 Karma

pradeepkumarg
Influencer

index=_internal sourcetype=scheduler

Start with the above search. You can then look how frequent a search is running by doing time chart on the savedsearch_name.

run_time, result_count are few other parameters you can look at to figure out expensive searches.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...