How to view the currently running search of Splunk and display the amount of memory consumed during the execution of this search command? Based on this information, I would like to pause some searches with high memory usage.
Alerts for splunk admins has an example for historical searches using the introspection data. Refer to my signature for a link
Hi @spl_stu,
as you can read at https://docs.splunk.com/Documentation/Splunk/9.0.4/RESTREF/RESTsearch#search.2Fjobs , you can use REST API to extract this kind of information.
So try:
| REST /services/search/jobs
Then you can choose the information you need.
Ciao.
Giuseppe
Hi @spl_stu,
good for you, see next time!
Please accept one answer for the other people of Community
Ciao and happy splunking
Giuseppe
P.S.: Karma Points are appreciated 😉