All Apps and Add-ons

What is the difference between Splunk's TTL settings?

sat94541
Communicator

There are several TTL (Time To Live). Can you tell us what the difference is between these and do these refer to the time the search has to live/execute or the search results?

· defaultSaveTTL
· defaultTTL
· eai:acl.ttl
· ttl

0 Karma

rbal_splunk
Splunk Employee
Splunk Employee

Below I have research for these TTL of Splunk

i)defaultTTL: This is the default ttl value of how long the search artifact artifact should be extended in response to the save control action, in second. 0 = indefinitely. Defaults to 604800 (1 week). This is defined in
----limits.conf----
default_save_ttl =
* How long the ttl for a search artifact should be extended in response to the
save control action, in second. 0 = indefinitely.
* Defaults to 604800 (1 week)

ii) defaultTTL : this seems to be defined from alert_actions.conf===
ttl = [p]
* Optional argument specifying the minimum time to live (in seconds)
of the search artifacts, if this action is triggered.
* If p follows integer, then integer is the number of scheduled periods.
* If no actions are triggered, the artifacts will have their ttl determined
by the "dispatch.ttl" attribute in savedsearches.conf.
* Defaults to 10p
* Defaults to 86400 (24 hours) for: email, rss
* Defaults to 600 (10 minutes) for: script
* Defaults to 120 (2 minutes) for: summary_index, populate_lookup

iii) eai:acl.ttl : this shows the value that Job selected based on it is is adhoc search , alert with action email , summary index etc.

iv) ttl : this is changing value like counter and it continually decrease indicating the time left until the search artifact Expires

Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...