It's not really a question, but could you please change your _internal log message:
The maximum number of concurrent scheduled searches has been reached (limits: historical=2, realtime=2). historical=21, realtime=0 ready-to-run scheduled searches are pending.
I have to add a regular expression to get the interesting historical value.
Only if someone has the same problem. I used this regex in order to get the value from the second historical pair.
| rex field=_raw "). historical=(?\d+)"
Please feel free to submit an enhancement request via the Splunk support portal .