Deployment Architecture

Search head cluster - changing dispatch.ttl for reports

patilsonali1729
Path Finder

I want to add the dispatch.ttl=1800 to few reports which otherwise keep the search artifacts for 2p time.
1. Is there a way to set this value from GUI while creating a report or once the report is created? Or changing the config on deployer and pushing it to all SHs is the only option?

Tags (1)
0 Karma
1 Solution

yannK
Splunk Employee
Splunk Employee

Yes.

Find the report in the settings > saved searches and reports.
on the report line, use the "advanced edit options"
You will be able to add exotic settings like dispatch.ttl, and customize them for this specific search

View solution in original post

yannK
Splunk Employee
Splunk Employee

Yes.

Find the report in the settings > saved searches and reports.
on the report line, use the "advanced edit options"
You will be able to add exotic settings like dispatch.ttl, and customize them for this specific search

patilsonali1729
Path Finder

Thanks! Just to clarify the steps-
1. setting -> Searches, reports, alerts
2. Find report name
3. click on edit
4. select Advanced Edit

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...