Splunk Search

Scheduled frequently vs scheduled real-time search load

Path Finder


I assume this has been asked several times before, but I haven’t found a good discussion on it…

What are the host load considerations to evaluate when:

running a scheduled search every 5 minutes, on a dataset -5m to now
running the same scheduled search rt to rt ?


Tags (3)


Here is a short presentation "Real Time in Splunk 4.1" explaining how it works.

I would say real-time will do the job with a bit less total load on your system as extra disk read is avoided. But big difference is real-time load is spread evenly, events are processed as they come in, while scheduled search does all 5min at one go (= can have some "spikes" on your system load).

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!