My scheduled job in Splunk DB connect app runs 3 times a day and pulls DB records to an Index.
Is there a way I can get the Search Job ID associated with the scheduled job ?
So that I can see how many records were fetched each time the scheduled search ran
I want to see the results something like:
DATE SID COUNT
01/04/2019 101 223
01/04/2019 102 226
01/04/2019 103 227
Basically I want anything unique associated with the results.
You can include | addinfo to your query which will add the time the search ran and the SID of that search.
View solution in original post
You should be able to see them in 'sid' field in index=_internal source="*dbx2* " and then use source/sourcetype/fields to match your scheduled search
index=_internal source="*dbx2* "