Splunk Search

How to identify the top aggressive scheduled searches in our environment in regards to frequency and resource utilization?

Path Finder

I have a lot of scheduled searches in one of our shared accounts.

How do you analyze which are the top aggressive searches with regards to frequency (rt, 5 min etc.) or resources (not restricted to specific sourcetype, host etc.)

My intention is to clear out some intensive alerts/reports.

0 Karma

Influencer

This app was built to identify searches with high resource utilization (among other things): https://splunkbase.splunk.com/app/2678/

0 Karma

Influencer

index=_internal sourcetype=scheduler

Start with the above search. You can then look how frequent a search is running by doing time chart on the savedsearch_name.

runtime, resultcount are few other parameters you can look at to figure out expensive searches.

0 Karma