- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to identify the top aggressive scheduled searches in our environment in regards to frequency and resource utilization?
aniketb
Path Finder
05-25-2016
07:06 AM
I have a lot of scheduled searches in one of our shared accounts.
How do you analyze which are the top aggressive searches with regards to frequency (rt, 5 min etc.) or resources (not restricted to specific sourcetype, host etc.)
My intention is to clear out some intensive alerts/reports.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

masonmorales
Influencer
05-25-2016
07:55 AM
This app was built to identify searches with high resource utilization (among other things): https://splunkbase.splunk.com/app/2678/
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

pradeepkumarg
Influencer
05-25-2016
07:14 AM
index=_internal sourcetype=scheduler
Start with the above search. You can then look how frequent a search is running by doing time chart on the savedsearch_name.
run_time, result_count are few other parameters you can look at to figure out expensive searches.
