Getting Data In

What is scheduler status=continued?

the_wolverine
Champion

In the scheduler logging, I see status=continued. What exactly does that mean?

1 Solution

emechler_splunk
Splunk Employee
Splunk Employee

Quoting from http://docs.splunk.com/Documentation/Splunk/6.1.1/Report/Configurethepriorityofscheduledreports:

Continuous scheduling is used for situations where problems arise when there's any gap in
the collection of report data. In general this is only important for reports that populate
summary indexes, though you may find other uses for it. When a report is enabled for
summary indexing, Splunk Enterprise changes its scheduling option to continuous
automatically.

When you see a "status=continued" event it refers to the case where a continuous search that was supposed to run at a given time wasn't and the system will come back to it later.

View solution in original post

emechler_splunk
Splunk Employee
Splunk Employee

Quoting from http://docs.splunk.com/Documentation/Splunk/6.1.1/Report/Configurethepriorityofscheduledreports:

Continuous scheduling is used for situations where problems arise when there's any gap in
the collection of report data. In general this is only important for reports that populate
summary indexes, though you may find other uses for it. When a report is enabled for
summary indexing, Splunk Enterprise changes its scheduling option to continuous
automatically.

When you see a "status=continued" event it refers to the case where a continuous search that was supposed to run at a given time wasn't and the system will come back to it later.

ben_leung
Builder

So should we expect in the scheduler log that there will be a status completed for the specified scheduled time?

0 Karma

nishitdarade
Explorer

Yes there will be a status completed.

0 Karma
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Deprecation of Splunk Observability Kubernetes “Classic Navigator” UI starting ...

Access to Splunk Observability Kubernetes “Classic Navigator” UI will no longer be available starting January ...

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...