Hi All,
We have removed real-time searching capability in our enterprise but the users havent yet removed their Realtime saved searches.
When I try to find the skipped searches, I get a list of searches that are being skipped since they are realtime.
Actually Im trying to figure out if there are still any searches being skipped in our premises due to any overload or so, which are not real-time.
Thus trying to find out searches being skipped apart form real-time.
Could you please suggest how I can achieve this???
I use this for scheduled searches (including datamodels), if that helps:
index="_internal" sourcetype="scheduler"
| eval scheduled=strftime(scheduled_time, "%Y-%m-%d %H:%M:%S")
| stats values(scheduled) as scheduled
values(savedsearch_name) as search_name
values(status) as status
values(reason) as reason
values(run_time) as run_time
values(dm_node) as dm_node
values(sid) as sid
by _time,savedsearch_name | sort -scheduled
| table scheduled, search_name, status, reason, run_time
I use this for scheduled searches (including datamodels), if that helps:
index="_internal" sourcetype="scheduler"
| eval scheduled=strftime(scheduled_time, "%Y-%m-%d %H:%M:%S")
| stats values(scheduled) as scheduled
values(savedsearch_name) as search_name
values(status) as status
values(reason) as reason
values(run_time) as run_time
values(dm_node) as dm_node
values(sid) as sid
by _time,savedsearch_name | sort -scheduled
| table scheduled, search_name, status, reason, run_time