Knowledge Management

How can I change default lifetime of job?

simon_b
Path Finder

I have the problem that my scheduled searches all have a lifetime of 10 days.

This is the case for searches that run once every day but also searches that run every 4 hours. Changing the "Expires" value doesn't affect that 10 days lifetime.

How can I change the default lifetime of my scheduled searches?

Labels (1)
0 Karma
1 Solution

inventsekar
SplunkTrust
SplunkTrust

Hi .. please check:https://www.splunk.com/en_us/blog/conf-splunklive/how-long-does-my-search-live-default-search-ttl.ht...

You can change a ttl either by setting an individual value for a search when you save it, set a dispatch.ttl value (either global or for an individual search) in savedsearches.conf or the [search] or [subsearch] stanzas in limits.conf (ttl or remote_ttl in [search] or ttl in [subsearch].) Have a look at the documentation in savedsearches.conf.spec and limits.conf.spec for more on how to specify these values. Most are given in seconds, except for dispatch.ttl which can also specify the number of schedule periods (like “2p”.)

@simon_b

View solution in original post

inventsekar
SplunkTrust
SplunkTrust

Hi .. please check:https://www.splunk.com/en_us/blog/conf-splunklive/how-long-does-my-search-live-default-search-ttl.ht...

You can change a ttl either by setting an individual value for a search when you save it, set a dispatch.ttl value (either global or for an individual search) in savedsearches.conf or the [search] or [subsearch] stanzas in limits.conf (ttl or remote_ttl in [search] or ttl in [subsearch].) Have a look at the documentation in savedsearches.conf.spec and limits.conf.spec for more on how to specify these values. Most are given in seconds, except for dispatch.ttl which can also specify the number of schedule periods (like “2p”.)

@simon_b

Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

🍂 Fall into November with a fresh lineup of Community Office Hours, Tech Talks, and Webinars we’ve ...

Transform your security operations with Splunk Enterprise Security

Hi Splunk Community, Splunk Platform has set a great foundation for your security operations. With the ...

Splunk Admins and App Developers | Earn a $35 gift card!

Splunk, in collaboration with ESG (Enterprise Strategy Group) by TechTarget, is excited to announce a ...