Splunk Search

How to identify the top aggressive scheduled searches in our environment in regards to frequency and resource utilization?

aniketb
Path Finder

I have a lot of scheduled searches in one of our shared accounts.

How do you analyze which are the top aggressive searches with regards to frequency (rt, 5 min etc.) or resources (not restricted to specific sourcetype, host etc.)

My intention is to clear out some intensive alerts/reports.

0 Karma

masonmorales
Influencer

This app was built to identify searches with high resource utilization (among other things): https://splunkbase.splunk.com/app/2678/

0 Karma

pradeepkumarg
Influencer

index=_internal sourcetype=scheduler

Start with the above search. You can then look how frequent a search is running by doing time chart on the savedsearch_name.

run_time, result_count are few other parameters you can look at to figure out expensive searches.

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...