Splunk Search

How to view the currently running search of Splunk and display the amount of memory consumed during search command?

spl_stu
Explorer

How to view the currently running search of Splunk and display the amount of memory consumed during the execution of this search command? Based on this information, I would like to pause some searches with high memory usage.

0 Karma

gjanders
SplunkTrust
SplunkTrust

Alerts for splunk admins has an example for historical searches using the introspection data. Refer to my signature for a link 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @spl_stu,

as you can read at https://docs.splunk.com/Documentation/Splunk/9.0.4/RESTREF/RESTsearch#search.2Fjobs , you can use REST API to extract this kind of information.

So try:

| REST /services/search/jobs

 Then you can choose the information you need.

Ciao.

Giuseppe

spl_stu
Explorer
Okay, thank you for your suggestion. This issue has been resolved so far.
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @spl_stu,

good for you, see next time!

Please accept one answer for the other people of Community

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Get Updates on the Splunk Community!

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...