Dashboards & Visualizations

How to refresh saved search in Splunk 6.5.1?

nmouli
Explorer

Hi -

I have saved search scheduled for every 10min but the latest results are not getting reflected in dashboard.

Tried using the refresh.auto.interval option but it was deprecated in Splunk 6.5.1 and since all the panels are using post processing search, can't see the refresh delay options in edit panels.

please suggest. Thanks in advance!

0 Karma
1 Solution

nmouli
Explorer

I have tried with refresh tag under search tag and it works.

< search id="base_search" ref="saved_search" >
< refresh> 60s < /refresh>
< /search>

View solution in original post

0 Karma

nmouli
Explorer

I have tried with refresh tag under search tag and it works.

< search id="base_search" ref="saved_search" >
< refresh> 60s < /refresh>
< /search>

0 Karma

aaraneta_splunk
Splunk Employee
Splunk Employee

@nmouli - Is this the working solution to your question? If yes, please don't forget to click "Accept" to resolve this question.

Also, for future reference, when posting a sample code wrapped in brackets <search> or sample search with special characters such as an asterisk *, you should wrap it in a Code Sample for proper formatting. Simply click on the Code Sample icon to the right of the Blockquote icon in the formatting toolbar. Thanks.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...