Getting Data In

What is scheduler status=continued?

the_wolverine
Champion

In the scheduler logging, I see status=continued. What exactly does that mean?

1 Solution

emechler_splunk
Splunk Employee
Splunk Employee

Quoting from http://docs.splunk.com/Documentation/Splunk/6.1.1/Report/Configurethepriorityofscheduledreports:

Continuous scheduling is used for situations where problems arise when there's any gap in
the collection of report data. In general this is only important for reports that populate
summary indexes, though you may find other uses for it. When a report is enabled for
summary indexing, Splunk Enterprise changes its scheduling option to continuous
automatically.

When you see a "status=continued" event it refers to the case where a continuous search that was supposed to run at a given time wasn't and the system will come back to it later.

View solution in original post

emechler_splunk
Splunk Employee
Splunk Employee

Quoting from http://docs.splunk.com/Documentation/Splunk/6.1.1/Report/Configurethepriorityofscheduledreports:

Continuous scheduling is used for situations where problems arise when there's any gap in
the collection of report data. In general this is only important for reports that populate
summary indexes, though you may find other uses for it. When a report is enabled for
summary indexing, Splunk Enterprise changes its scheduling option to continuous
automatically.

When you see a "status=continued" event it refers to the case where a continuous search that was supposed to run at a given time wasn't and the system will come back to it later.

ben_leung
Builder

So should we expect in the scheduler log that there will be a status completed for the specified scheduled time?

0 Karma

nishitdarade
Explorer

Yes there will be a status completed.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...