Hi,
I assume this has been asked several times before, but I haven’t found a good discussion on it…
What are the host load considerations to evaluate when:
running a scheduled search every 5 minutes, on a dataset -5m to now
vs
running the same scheduled search rt to rt ?
Thanks,
Mark
Here is a short presentation "Real Time in Splunk 4.1" explaining how it works.
I would say real-time will do the job with a bit less total load on your system as extra disk read is avoided. But big difference is real-time load is spread evenly, events are processed as they come in, while scheduled search does all 5min at one go (= can have some "spikes" on your system load).