Getting Data In

What is scheduler status=continued?

the_wolverine
Champion

In the scheduler logging, I see status=continued. What exactly does that mean?

1 Solution

emechler_splunk
Splunk Employee
Splunk Employee

Quoting from http://docs.splunk.com/Documentation/Splunk/6.1.1/Report/Configurethepriorityofscheduledreports:

Continuous scheduling is used for situations where problems arise when there's any gap in
the collection of report data. In general this is only important for reports that populate
summary indexes, though you may find other uses for it. When a report is enabled for
summary indexing, Splunk Enterprise changes its scheduling option to continuous
automatically.

When you see a "status=continued" event it refers to the case where a continuous search that was supposed to run at a given time wasn't and the system will come back to it later.

View solution in original post

emechler_splunk
Splunk Employee
Splunk Employee

Quoting from http://docs.splunk.com/Documentation/Splunk/6.1.1/Report/Configurethepriorityofscheduledreports:

Continuous scheduling is used for situations where problems arise when there's any gap in
the collection of report data. In general this is only important for reports that populate
summary indexes, though you may find other uses for it. When a report is enabled for
summary indexing, Splunk Enterprise changes its scheduling option to continuous
automatically.

When you see a "status=continued" event it refers to the case where a continuous search that was supposed to run at a given time wasn't and the system will come back to it later.

ben_leung
Builder

So should we expect in the scheduler log that there will be a status completed for the specified scheduled time?

0 Karma

nishitdarade
Explorer

Yes there will be a status completed.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...