My scheduled job in Splunk DB connect app runs 3 times a day and pulls DB records to an Index.
say index=my_index
Is there a way I can get the Search Job ID associated with the scheduled job ?
So that I can see how many records were fetched each time the scheduled search ran
I want to see the results something like:
DATE SID COUNT
01/04/2019 101 223
01/04/2019 102 226
01/04/2019 103 227
Basically I want anything unique associated with the results.
You can include | addinfo
to your query which will add the time the search ran and the SID of that search.
https://docs.splunk.com/Documentation/Splunk/7.2.4/SearchReference/Addinfo
You should be able to see them in 'sid' field in index=_internal source="*dbx2* "
and then use source/sourcetype/fields to match your scheduled search
You can include | addinfo
to your query which will add the time the search ran and the SID of that search.
https://docs.splunk.com/Documentation/Splunk/7.2.4/SearchReference/Addinfo