Dashboards & Visualizations

Realtime saved search on dashboard

sc0tt
Builder

I've come across several posts about this topic but I can't seem to find a good example of how to get this to work. I want to create a realtime saved search for the current day on a dashboard so that it doesn't have to run each time the dashboard is opened. I created a realtime search and scheduled it with the time as rt-0d@d and rt but when I view the results and use the HiddenSavedSearch module it looks like it is only showing the most recent streamed results and not from the beginning of the day.

Am I missing something? How can I get this to work?

0 Karma
1 Solution

nmistry_splunk
Splunk Employee
Splunk Employee

For performance results, Splunk does not perform back fill for scheduled realtime searches. If you want it backfill, you will have to set dispatch.rt_backfill=1 in your search definition in savedsearches.conf

View solution in original post

nmistry_splunk
Splunk Employee
Splunk Employee

For performance results, Splunk does not perform back fill for scheduled realtime searches. If you want it backfill, you will have to set dispatch.rt_backfill=1 in your search definition in savedsearches.conf

sc0tt
Builder

I needed to include enableSched = 1 as well and restart Splunk for the change to take. Saving the schedule from the reports menu removed the backfill flag.

0 Karma

sc0tt
Builder

I have included dispatch.rt_backfill=1 in my savedsearches.conf but it doesn't seem like this is working. Any ideas? I'm using Splunk 6 if that matters.

sc0tt
Builder

Thanks for your help.

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...