Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Excessive Jobs / Optimized Search

$
0
0
I have optimised my search as I can see but I have now run into a problem wherein my search is spawning 39 jobs on each refresh. This is obviously killing resources and causes my dashboard panels to take longer than expected to run and does cause the user limits and search limits to be run. As a consequence I have disabled my app until I can understand why this is happening. This is a full extract of the dashboard that I have created, with a couple of things like specific accounts adjusted here and there. When this dashboard is opened it will generate 39 searches to the Job Queue. It will do the same on any type of refresh. What is happening here or what have I missed? I expected that by using a **search id** and then in each panel referring back to it using **search base** I could effectively make this 1 search and then have each panel generate based on the parameters.
This dashboards shows elevation index=windows sourcetype=WinEventLog EventCode IN(1102,4732,4728,4625,4720,4726,4755,4756,4776,4768) | fields dvc_nt_host Group_Domain Group_Name action src_user user _time $time_tok.earliest$$time_tok.latest$
-24h@hnow
Domain Admin Change (Last 24 hours) | search EventCode="4728" AND Group_Name="Domain Admins" AND action="success" | timechart dc(Group_Name) span=24h | appendpipe [stats count | where count=0]Domain Admin Change (Last 24 hours) | search EventCode="4728" AND Group_Name="Domain Admins" AND action="success" | table dvc_nt_host src_user user Group_Domain Group_Name _time | sort - _timeEnterprise Admin Change (Last 24 hours) | search EventCode="4756" AND Group_Name="Enterprise Admins" AND action="success" | timechart dc(Group_Name) span=24h | appendpipe [stats count | where count=0]Enterprise Admin Change (Last 24 hours) | search EventCode="4756" AND Group_Name="Enterprise Admins" AND action="success" | table dvc_nt_host src_user user Group_Domain Group_Name _time | sort - _timePrivilege Group Additions - group 1 | search EventCode IN(4755,4756,4728) [|inputlookup privgroup_group1.csv] | timechart dc(Group_Name) span=24h | appendpipe [stats count | where count=0]Privilege Group Additions - group 2 | search EventCode IN(4755,4756,4728) [|inputlookup privgroup_group2.csv] | timechart dc(Group_Name) span=24h | appendpipe [stats count | where count=0]Privilege Group Additions - group 3 | search EventCode IN(4755,4756,4728) [|inputlookup privgroup_group3.csv] | timechart dc(Group_Name) span=24h | appendpipe [stats count | where count=0]Event Logs Cleared | search EventCode="1102" | timechart dc(user) span=24h | appendpipe [stats count | where count=0]Internet Access Provided to Account | search EventCode="4728" AND Group_Name="internet" AND src_user!="admin" | timechart dc(user) span=24h | appendpipe [stats count | where count=0]User Account Creation | search EventCode="4720" src_user!="admin" | timechart dc(Group_Name) span=24h | appendpipe [stats count | where count=0]User Account Deletion | search EventCode="4726" src_user!="admin" src_user!="2nd_admin" src_user!="3rd_admin" | timechart dc(Group_Name) span=24h | appendpipe [stats count | where count=0]
Thanks in advance

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>