Splunk Search

Why are saved searches running on indexers?

Path Finder


when i run ps aux | grep "scheduler" on indexer i see some searches running .. I am wondering how come saved searches are running on indexers like

1.) what might be the reason?

2.) saved searches shouldn't be running on indexers? only on search heads?

3.) is there any search to find out why all the saved searches are running on indexers?

4.) how to stop these searches running on indexers?

0 Karma

Splunk Employee
Splunk Employee

Most likely these are from TA's you have installed in your environment.

To validate this, and see what is running, use btool on your indexers

$splunk_home$/bin/splunk btool savedsearches list --debug

That will show you what is running and what files this is running from. You can remediate by this.

State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!