Hi
I noticed a quite a number job running in the background attributed to the macro "modular_action_invocations". From the job activity , the jobs are owned by users and link to the search Apps. And some of these jobs take quite a far bit of time to run , in very wide range of seconds to hours to complete. It had affects our operation when the concurrent search limit is reached.
Appreciate some help if anyone can provide more information on the marco. I'm aware that I can increase the CPU/hardware resource to mitigate the situation but would like to find out more into it.
Thanks Jim
Additional note : Not sure if it is related , - most my team analysts are using the incident review module on Enterprise security to manage the notable events. At any point of time , there are 3-4 analysts working on it.
Macro : modular_action_invocations(2) Apps : Splunk_SA_CIM
... View more