Splunk Search

Why are saved searches running on indexers?

kteng2024
Path Finder

Hi,

when i run ps aux | grep "scheduler" on indexer i see some searches running .. I am wondering how come saved searches are running on indexers like

1.) what might be the reason?

2.) saved searches shouldn't be running on indexers? only on search heads?

3.) is there any search to find out why all the saved searches are running on indexers?

4.) how to stop these searches running on indexers?

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Most likely these are from TA's you have installed in your environment.

To validate this, and see what is running, use btool on your indexers

$splunk_home$/bin/splunk btool savedsearches list --debug

That will show you what is running and what files this is running from. You can remediate by this.

Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...