Dashboards & Visualizations

Can someone help me on basic questions about search refresh?

jip31
Motivator

Hi

 

I use a search refresh like this

 

          <earliest>-15m</earliest>
          <latest>now</latest>
          <refresh>30s</refresh>
          <refreshType>delay</refreshType>

 

 I have 2 questions :

1) Is the refresh delay starts from the search saving? 

2) Is it possible to synchronize th search delay between 2 searches because actually I use the same refresh delay between 2 searches but the refresh doesn't occurs in the same time

Thanks

Tags (3)
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

If the two searches are based on the same search, but with different outputs, then you can make a base search used by both searches and apply the refresh setting to the base search, which will then cause both post processing searches to execute at the same point.

 

View solution in original post

0 Karma

bowesmana
SplunkTrust
SplunkTrust

If the two searches are based on the same search, but with different outputs, then you can make a base search used by both searches and apply the refresh setting to the base search, which will then cause both post processing searches to execute at the same point.

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @jip31,

search delay is a cron definition, so it's fixes every 30 seconds (in your case), it isn't influenced by the search duration.

It isn't possible to synchronize the refreshes of two searches, you have to measure the average duration of each search and choose the delays.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...