Splunk Search

How to identify the top aggressive scheduled searches in our environment in regards to frequency and resource utilization?

Path Finder

I have a lot of scheduled searches in one of our shared accounts.

How do you analyze which are the top aggressive searches with regards to frequency (rt, 5 min etc.) or resources (not restricted to specific sourcetype, host etc.)

My intention is to clear out some intensive alerts/reports.

0 Karma


This app was built to identify searches with high resource utilization (among other things): https://splunkbase.splunk.com/app/2678/

0 Karma


index=_internal sourcetype=scheduler

Start with the above search. You can then look how frequent a search is running by doing time chart on the savedsearch_name.

run_time, result_count are few other parameters you can look at to figure out expensive searches.

0 Karma
Get Updates on the Splunk Community!

3 Ways to Make OpenTelemetry Even Better

My role as an Observability Specialist at Splunk provides me with the opportunity to work with customers of ...

What's New in Splunk Cloud Platform 9.2.2406?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2406 with many ...

Enterprise Security Content Update (ESCU) | New Releases

In August, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...