Splunk Search

How to track the run times of saved and scheduled searches?

rwi
Engager

I am looking to track the run times of analytics as well as create logs of the run times of the analytics in order to create a dashboard where you can see the run times of these saved searches as well as other relevant statistics (average length of time of search).  Any experience in doing this?

0 Karma

rwi
Engager

Rich,

This worked okay! However, what is the difference between utilizing the scheduler.log and 
|rest /servicesNS/-/-/saved/searches ?

I am not getting the same results back concerning the scheduled searches. Some in scheduler.log do not appear in the |rest......

@richgalloway 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The API shows what searches are configured, whereas the log shows what executed.

I don't know why some searches would be in the log, but not in the API.

---
If this reply helps you, Karma would be appreciated.
0 Karma

richgalloway
SplunkTrust
SplunkTrust

If I understand the use case correctly, the scheduler log should have that information.  Start with index=_internal source=*scheduler.log

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...