14.1 Overview

The Active Search Jobs feature in Sentinel lists all the active event search jobs running in the system, including searches that are initiated when users perform activities, such as:

The Active Search Jobs feature helps you monitor search activities and determine whether a search is not retrieving events as expected or whether a search is retrieving more than the expected events, which might indicate that the search needs to be tuned. It also helps you determine if too many searches are running and helps identify long-running searches that might slow down the system. Searches that consume a lot of memory are a potential liability to a healthy system and should be carefully reviewed to ensure that the search query is specified properly. You can also stop the searches that are no longer needed and thereby free up system resources.