Dashboards & Visualizations

Realtime saved search on dashboard

sc0tt
Builder

I've come across several posts about this topic but I can't seem to find a good example of how to get this to work. I want to create a realtime saved search for the current day on a dashboard so that it doesn't have to run each time the dashboard is opened. I created a realtime search and scheduled it with the time as rt-0d@d and rt but when I view the results and use the HiddenSavedSearch module it looks like it is only showing the most recent streamed results and not from the beginning of the day.

Am I missing something? How can I get this to work?

0 Karma
1 Solution

nmistry_splunk
Splunk Employee
Splunk Employee

For performance results, Splunk does not perform back fill for scheduled realtime searches. If you want it backfill, you will have to set dispatch.rt_backfill=1 in your search definition in savedsearches.conf

View solution in original post

nmistry_splunk
Splunk Employee
Splunk Employee

For performance results, Splunk does not perform back fill for scheduled realtime searches. If you want it backfill, you will have to set dispatch.rt_backfill=1 in your search definition in savedsearches.conf

sc0tt
Builder

I needed to include enableSched = 1 as well and restart Splunk for the change to take. Saving the schedule from the reports menu removed the backfill flag.

0 Karma

sc0tt
Builder

I have included dispatch.rt_backfill=1 in my savedsearches.conf but it doesn't seem like this is working. Any ideas? I'm using Splunk 6 if that matters.

sc0tt
Builder

Thanks for your help.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...