<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Scheduled search with only | inputlookup in the search returns zero results in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Scheduled-search-with-only-inputlookup-in-the-search-returns/m-p/704947#M20872</link>
    <description>&lt;P&gt;It's under my username, with Admin privileges.&lt;/P&gt;</description>
    <pubDate>Thu, 21 Nov 2024 12:27:58 GMT</pubDate>
    <dc:creator>SteveBowser</dc:creator>
    <dc:date>2024-11-21T12:27:58Z</dc:date>
    <item>
      <title>Scheduled search with only | inputlookup in the search returns zero results</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Scheduled-search-with-only-inputlookup-in-the-search-returns/m-p/704938#M20870</link>
      <description>&lt;P&gt;I created a scheduled search that reads 2 input lookup csv files. It returns zero results when I look at the "View Recent"/Job Manager. When I run it by clicking the "Run" selection, I get the results that I'm looking for. What am I overlooking?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 11:39:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Scheduled-search-with-only-inputlookup-in-the-search-returns/m-p/704938#M20870</guid>
      <dc:creator>SteveBowser</dc:creator>
      <dc:date>2024-11-21T11:39:07Z</dc:date>
    </item>
    <item>
      <title>Re: Scheduled search with only | inputlookup in the search returns zero results</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Scheduled-search-with-only-inputlookup-in-the-search-returns/m-p/704946#M20871</link>
      <description>&lt;P&gt;Which user does the scheduled search run as and do they have access to the lookup files?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 12:25:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Scheduled-search-with-only-inputlookup-in-the-search-returns/m-p/704946#M20871</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-11-21T12:25:40Z</dc:date>
    </item>
    <item>
      <title>Re: Scheduled search with only | inputlookup in the search returns zero results</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Scheduled-search-with-only-inputlookup-in-the-search-returns/m-p/704947#M20872</link>
      <description>&lt;P&gt;It's under my username, with Admin privileges.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 12:27:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Scheduled-search-with-only-inputlookup-in-the-search-returns/m-p/704947#M20872</guid>
      <dc:creator>SteveBowser</dc:creator>
      <dc:date>2024-11-21T12:27:58Z</dc:date>
    </item>
    <item>
      <title>Re: Scheduled search with only | inputlookup in the search returns zero results</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Scheduled-search-with-only-inputlookup-in-the-search-returns/m-p/704948#M20873</link>
      <description>&lt;P&gt;Sorry, I have access to the files.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 12:28:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Scheduled-search-with-only-inputlookup-in-the-search-returns/m-p/704948#M20873</guid>
      <dc:creator>SteveBowser</dc:creator>
      <dc:date>2024-11-21T12:28:53Z</dc:date>
    </item>
    <item>
      <title>Re: Scheduled search with only | inputlookup in the search returns zero results</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Scheduled-search-with-only-inputlookup-in-the-search-returns/m-p/705432#M20939</link>
      <description>&lt;P&gt;There are no timestamps in the lookup table. When I plug one in, I get the desired results.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2024 18:27:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Scheduled-search-with-only-inputlookup-in-the-search-returns/m-p/705432#M20939</guid>
      <dc:creator>SteveBowser</dc:creator>
      <dc:date>2024-11-27T18:27:26Z</dc:date>
    </item>
    <item>
      <title>Re: Scheduled search with only | inputlookup in the search returns zero results</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Scheduled-search-with-only-inputlookup-in-the-search-returns/m-p/706385#M21041</link>
      <description>&lt;P&gt;Answering my own question here - it needs to have dates to display results. In the end, I wrote the results to a summary index in a scheduled search using | collect index=test_summary addtime=true.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2024 18:17:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Scheduled-search-with-only-inputlookup-in-the-search-returns/m-p/706385#M21041</guid>
      <dc:creator>SteveBowser</dc:creator>
      <dc:date>2024-12-09T18:17:23Z</dc:date>
    </item>
  </channel>
</rss>

