Dashboards & Visualizations

Realtime saved search on dashboard

sc0tt
Builder

I've come across several posts about this topic but I can't seem to find a good example of how to get this to work. I want to create a realtime saved search for the current day on a dashboard so that it doesn't have to run each time the dashboard is opened. I created a realtime search and scheduled it with the time as rt-0d@d and rt but when I view the results and use the HiddenSavedSearch module it looks like it is only showing the most recent streamed results and not from the beginning of the day.

Am I missing something? How can I get this to work?

0 Karma
1 Solution

nmistry_splunk
Splunk Employee
Splunk Employee

For performance results, Splunk does not perform back fill for scheduled realtime searches. If you want it backfill, you will have to set dispatch.rt_backfill=1 in your search definition in savedsearches.conf

View solution in original post

nmistry_splunk
Splunk Employee
Splunk Employee

For performance results, Splunk does not perform back fill for scheduled realtime searches. If you want it backfill, you will have to set dispatch.rt_backfill=1 in your search definition in savedsearches.conf

sc0tt
Builder

I needed to include enableSched = 1 as well and restart Splunk for the change to take. Saving the schedule from the reports menu removed the backfill flag.

0 Karma

sc0tt
Builder

I have included dispatch.rt_backfill=1 in my savedsearches.conf but it doesn't seem like this is working. Any ideas? I'm using Splunk 6 if that matters.

sc0tt
Builder

Thanks for your help.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...