index=_internal source=*license_usage.log type=Usage earliest=-20d | eval MB = b/1024/1024 | rename s AS source | timechart span=1d sum(b) AS "Total MB used" by source
index=_internal ( sourcetype=scheduler alert_actions="email" ) OR ( sourcetype=splunk_python "sendemail" )
サーチ文字列 | delete
http://docs.splunk.com/Documentation/Splunk/latest/Alert/Configuringscriptedalerts
サーチしたら「waiting for queued job to start...」とでる | 同時実行数をこえてサーチが実行された。ひたすら待つかパラメータの調整を |