Hi All,
Need some info regarding thread_id in scheduler.log and how it is being assigned.
Sample Events 1:
02-03-2016 08:40:01.341 +0000 INFO SavedSplunker - savedsearch_id="admin;search;SS_1minute_23", user="admin", app="search", savedsearch_name="SS_1minute_23", status=success, digest_mode=1, scheduled_time=1454488800, dispatch_time=1454488801, run_time=0.178, result_count=1, alert_actions="", sid="scheduler_adminsearch_RMD5fe320a1798d45e4e_at_1454488800_189", suppressed=0, thread_id="AlertNotifierWorker-1"
02-03-2016 08:40:01.340 +0000 INFO SavedSplunker - savedsearch_id="admin;search;SS_test_threadid_3", user="admin", app="search", savedsearch_name="SS_test_threadid_3", status=success, digest_mode=1, scheduled_time=1454488800, dispatch_time=1454488801, run_time=0.156, result_count=1, alert_actions="", sid="scheduler_adminsearch_RMD506c18cc48c92c389_at_1454488800_190", suppressed=0, thread_id="AlertNotifierWorker-0"
Sample Events 2:
02-03-2016 08:59:01.219 +0000 INFO SavedSplunker - savedsearch_id="admin;search;SS_1minute_23", user="admin", app="search", savedsearch_name="SS_1minute_23", status=success, digest_mode=1, scheduled_time=1454489940, dispatch_time=1454489941, run_time=0.089, result_count=1, alert_actions="", sid="scheduler_adminsearch_RMD5fe320a1798d45e4e_at_1454489940_239", suppressed=0, thread_id="AlertNotifierWorker-0"
02-03-2016 08:59:01.211 +0000 INFO SavedSplunker - savedsearch_id="admin;search;SS_23", user="admin", app="search", savedsearch_name="SS_23", status=success, digest_mode=1, scheduled_time=1454489940, dispatch_time=1454489941, run_time=0.087, result_count=1, alert_actions="", sid="scheduler_adminsearch_RMD510bfa07112c26c31_at_1454489940_238", suppressed=0, thread_id="AlertNotifierWorker-0"
There are 14 thread_ids in the name of Alertnotifierworker-0 , Alertnotifierworker-1, Alertnotifierworker-2 … Alertnotifierworker-13.
We have seen scenarios like the scheduled_time and dispatch_time of a savedsearch/alert is the same, thread_id is getting incremented.
(E.g: Alertnotifierworker-0, Alertnotifierworker-1, Alertnotifierworker-2 … Alertnotifierworker-13)
However, in some cases, we have only one thread_id for all these savedsearch/alerts with same scheduled_time (E.g: Alertnotifierworker-0)
When would Splunk assign same thread_id and different thread_id for scheduled searches/alerts?
... View more