Dashboards & Visualizations

Saved search not writing output to the lookup file

spkriyaz
Path Finder

Hi,

Absolutely strange 😞

I have a search which writes the output to the lookup file, if I run this search in search head it writes the output to the lookup file BUT if I save this search as an alert and run it then it is not writing it to the lookup file even if the alert is triggered and search has ran successfully.

Any idea?

Thanks, 

Tags (1)
0 Karma
1 Solution

spkriyaz
Path Finder

Found the issue by analyzing _internal log, looks like I have set 24 hours as expiry for most of my saved searches which has filled the disk quota. My user has 1000MB disk quota limit which I was crossing. I have purged the old jobs in Activity-> jobs which has freed the disk quota now.

This solves the issue now 🙂

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @spkriyaz,

I think that your alert is in the same search head where you run the search.

check in [Activity -- Triggered Alert] if there's the run of your alert and if there are results.

Then, did you created the Lookup Definition related to your lookup?

Ciao.

Giuseppe

0 Karma

spkriyaz
Path Finder

Found the issue by analyzing _internal log, looks like I have set 24 hours as expiry for most of my saved searches which has filled the disk quota. My user has 1000MB disk quota limit which I was crossing. I have purged the old jobs in Activity-> jobs which has freed the disk quota now.

This solves the issue now 🙂

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...