Splunk Search

Why are saved searches running on indexers?

Path Finder


when i run ps aux | grep "scheduler" on indexer i see some searches running .. I am wondering how come saved searches are running on indexers like

1.) what might be the reason?

2.) saved searches shouldn't be running on indexers? only on search heads?

3.) is there any search to find out why all the saved searches are running on indexers?

4.) how to stop these searches running on indexers?

0 Karma

Splunk Employee
Splunk Employee

Most likely these are from TA's you have installed in your environment.

To validate this, and see what is running, use btool on your indexers

$splunk_home$/bin/splunk btool savedsearches list --debug

That will show you what is running and what files this is running from. You can remediate by this.

Get Updates on the Splunk Community!

Routing Data to Different Splunk Indexes in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...

Getting Started with AIOps: Event Correlation Basics and Alert Storm Detection in ...

Getting Started with AIOps:Event Correlation Basics and Alert Storm Detection in Splunk IT Service ...

Register to Attend BSides SPL 2022 - It's all Happening October 18!

Join like-minded individuals for technical sessions on everything Splunk!  This is a community-led and run ...