Getting Data In

What is scheduler status=continued?

the_wolverine
Champion

In the scheduler logging, I see status=continued. What exactly does that mean?

1 Solution

emechler_splunk
Splunk Employee
Splunk Employee

Quoting from http://docs.splunk.com/Documentation/Splunk/6.1.1/Report/Configurethepriorityofscheduledreports:

Continuous scheduling is used for situations where problems arise when there's any gap in
the collection of report data. In general this is only important for reports that populate
summary indexes, though you may find other uses for it. When a report is enabled for
summary indexing, Splunk Enterprise changes its scheduling option to continuous
automatically.

When you see a "status=continued" event it refers to the case where a continuous search that was supposed to run at a given time wasn't and the system will come back to it later.

View solution in original post

emechler_splunk
Splunk Employee
Splunk Employee

Quoting from http://docs.splunk.com/Documentation/Splunk/6.1.1/Report/Configurethepriorityofscheduledreports:

Continuous scheduling is used for situations where problems arise when there's any gap in
the collection of report data. In general this is only important for reports that populate
summary indexes, though you may find other uses for it. When a report is enabled for
summary indexing, Splunk Enterprise changes its scheduling option to continuous
automatically.

When you see a "status=continued" event it refers to the case where a continuous search that was supposed to run at a given time wasn't and the system will come back to it later.

ben_leung
Builder

So should we expect in the scheduler log that there will be a status completed for the specified scheduled time?

0 Karma

nishitdarade
Explorer

Yes there will be a status completed.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...