Dashboards & Visualizations

Saved search not writing output to the lookup file

spkriyaz
Path Finder

Hi,

Absolutely strange 😞

I have a search which writes the output to the lookup file, if I run this search in search head it writes the output to the lookup file BUT if I save this search as an alert and run it then it is not writing it to the lookup file even if the alert is triggered and search has ran successfully.

Any idea?

Thanks, 

Tags (1)
0 Karma
1 Solution

spkriyaz
Path Finder

Found the issue by analyzing _internal log, looks like I have set 24 hours as expiry for most of my saved searches which has filled the disk quota. My user has 1000MB disk quota limit which I was crossing. I have purged the old jobs in Activity-> jobs which has freed the disk quota now.

This solves the issue now 🙂

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @spkriyaz,

I think that your alert is in the same search head where you run the search.

check in [Activity -- Triggered Alert] if there's the run of your alert and if there are results.

Then, did you created the Lookup Definition related to your lookup?

Ciao.

Giuseppe

0 Karma

spkriyaz
Path Finder

Found the issue by analyzing _internal log, looks like I have set 24 hours as expiry for most of my saved searches which has filled the disk quota. My user has 1000MB disk quota limit which I was crossing. I have purged the old jobs in Activity-> jobs which has freed the disk quota now.

This solves the issue now 🙂

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...