Splunk Search

How to identify the top aggressive scheduled searches in our environment in regards to frequency and resource utilization?

aniketb
Path Finder

I have a lot of scheduled searches in one of our shared accounts.

How do you analyze which are the top aggressive searches with regards to frequency (rt, 5 min etc.) or resources (not restricted to specific sourcetype, host etc.)

My intention is to clear out some intensive alerts/reports.

0 Karma

masonmorales
Influencer

This app was built to identify searches with high resource utilization (among other things): https://splunkbase.splunk.com/app/2678/

0 Karma

pradeepkumarg
Influencer

index=_internal sourcetype=scheduler

Start with the above search. You can then look how frequent a search is running by doing time chart on the savedsearch_name.

run_time, result_count are few other parameters you can look at to figure out expensive searches.

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...