Scheduled frequently vs scheduled real-time search load

I assume this has been asked several times before, but I haven’t found a good discussion on it…

What are the host load considerations to evaluate when:

running a scheduled search every 5 minutes, on a dataset -5m to now
running the same scheduled search rt to rt ?


Here is a short presentation "Real Time in Splunk 4.1" explaining how it works.

I would say real-time will do the job with a bit less total load on your system as extra disk read is avoided. But big difference is real-time load is spread evenly, events are processed as they come in, while scheduled search does all 5min at one go (= can have some "spikes" on your system load).

