<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Does the map command support real-time search and is it streaming? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Does-the-map-command-support-real-time-search-and-is-it/m-p/148894#M41622</link>
    <description>&lt;P&gt;From the comments in &lt;A href="http://answers.splunk.com/answers/170274/why-is-this-real-time-search-producing-zero-result.html"&gt;this answer&lt;/A&gt;, it appears that &lt;CODE&gt;map&lt;/CODE&gt; doesn't start it's search until the outer search completes. Because a real-time search never completes, the search triggered by the &lt;CODE&gt;map&lt;/CODE&gt; command never runs.&lt;/P&gt;

&lt;P&gt;So, no. Unfortunately the &lt;CODE&gt;map&lt;/CODE&gt; command is not supported in real-time searches.&lt;/P&gt;</description>
    <pubDate>Wed, 20 May 2015 15:25:44 GMT</pubDate>
    <dc:creator>curtisb1024</dc:creator>
    <dc:date>2015-05-20T15:25:44Z</dc:date>
    <item>
      <title>Does the map command support real-time search and is it streaming?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Does-the-map-command-support-real-time-search-and-is-it/m-p/148892#M41620</link>
      <description>&lt;P&gt;I am trying to use the map command to trigger a new search each time a new event comes through to Splunk. The new search would be a saved search which triggers an email.&lt;/P&gt;

&lt;P&gt;The whole search works for the initial set of data in the index, but when new data comes in, the saved search is not triggered. Does the map command support real-time search and is it streaming?&lt;/P&gt;

&lt;P&gt;search&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=abc |fields to,subject,message
|map savedsearchabc
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;saved search&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;|sendemail to="$Address$" subject="$msg$" message="$msg$
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 23 Feb 2015 13:59:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Does-the-map-command-support-real-time-search-and-is-it/m-p/148892#M41620</guid>
      <dc:creator>spyme72</dc:creator>
      <dc:date>2015-02-23T13:59:25Z</dc:date>
    </item>
    <item>
      <title>Re: Does the map command support real-time search and is it streaming?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Does-the-map-command-support-real-time-search-and-is-it/m-p/148893#M41621</link>
      <description>&lt;P&gt;Hi -&lt;/P&gt;

&lt;P&gt;Could you please let us know time is spent on running 1st search by looking at Job inspector? &lt;BR /&gt;
There could be possibility that saved search is not getting triggered. Information about skipped searches could be found from scheduler.log&lt;/P&gt;</description>
      <pubDate>Tue, 24 Feb 2015 06:52:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Does-the-map-command-support-real-time-search-and-is-it/m-p/148893#M41621</guid>
      <dc:creator>satishsdange</dc:creator>
      <dc:date>2015-02-24T06:52:20Z</dc:date>
    </item>
    <item>
      <title>Re: Does the map command support real-time search and is it streaming?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Does-the-map-command-support-real-time-search-and-is-it/m-p/148894#M41622</link>
      <description>&lt;P&gt;From the comments in &lt;A href="http://answers.splunk.com/answers/170274/why-is-this-real-time-search-producing-zero-result.html"&gt;this answer&lt;/A&gt;, it appears that &lt;CODE&gt;map&lt;/CODE&gt; doesn't start it's search until the outer search completes. Because a real-time search never completes, the search triggered by the &lt;CODE&gt;map&lt;/CODE&gt; command never runs.&lt;/P&gt;

&lt;P&gt;So, no. Unfortunately the &lt;CODE&gt;map&lt;/CODE&gt; command is not supported in real-time searches.&lt;/P&gt;</description>
      <pubDate>Wed, 20 May 2015 15:25:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Does-the-map-command-support-real-time-search-and-is-it/m-p/148894#M41622</guid>
      <dc:creator>curtisb1024</dc:creator>
      <dc:date>2015-05-20T15:25:44Z</dc:date>
    </item>
  </channel>
</rss>

