Splunk Search

How to use the new scheduler most efficently?



I've got hundreds of searches that are scheduled ervry night from 00:00 to 6:00. It does not matter when they will be finished unless it is before 7:00.
What is the best approach to use the new scheduler in Splunk 6.3 for this usecase? As far as understand it, it could be a good option to schedule all searches at 00:00 and setup a window of 6 hours. So the scheduler would be able to run the searches most efficently. Is this a correct assumption or could it cause problems to schedule all search at once?

Thanks in advance

0 Karma


Hi Heinz, that seems reasonable based on my reading of the documentation. More info can be found here: https://conf.splunk.com/session/2015/conf2015_PLucas_Splunk_SplunkEntWhatsNew_MakingTheMostOf.pdf

Please let me know if this helps!


Too me as well, but I'm not sure whether this is intended 😉
That's a great talk about the scheduler changes!

0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

March Community Office Hours Security Series Uncovered!

Hello Splunk Community! In March, Splunk Community Office Hours spotlighted our fabulous Splunk Threat ...

Stay Connected: Your Guide to April Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars in April. This post ...