Other Admin

saved search

SN1
Path Finder

I am not able to see the schedule of the saved searches although they are cron scheduled . so when i am saving again the saved search the time can be seen but after some time it just does not show.

SN1_0-1751518963428.png

 




Labels (1)
0 Karma

livehybrid
Super Champion

Hi @SN1 

I have seen this before in a couple of scenarios, the first is when a search is created using the API or uploaded in a custom app but the search is invalid or has a macro which cannot be expanded, this causes the scheduler to not schedule the search but it does provide an error in the log. Do any of these search names appear in the _internal log with any errors?

How did you create the search? Was it done via manual changes to savedsearches.conf? API? UI? The other time I have seen this is when it was created via the API or manually in the conf:

Regarding enableSched, if you added the searches via the API then there can be some complications:

If you use the "/services/saved/search" endpoint then you need to use is_scheduled=1 instead of enableSched=1

If you use the "/servicesNS/<user>/<app>/configs/conf-savedsearches" then you need to use enableSched=1 but also I'm not 100% sure if changes will take effect without a reload/restart/search toggle when using this endpoint? Your mileage may vary.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

SN1
Path Finder

actually there is one thing that i forget to tell that i have made indexer standalone that these saved searches i have copied from search head

0 Karma

Prewin27
Contributor

@SN1 

Does the user who created/modified the savedsearch have enough permissions?
Also whats the value of enableSched in savedsearches.conf. Make sure your search is having enableSched = 1 in savedsearches.conf.
#https://docs.splunk.com/Documentation/Splunk/9.4.2/Admin/Savedsearchesconf


Regards,
Prewin
Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

0 Karma

SN1
Path Finder

it is made by me I have admin role, searches are not disabled and enableSched = 1.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

When you edit the search in this state is it still initially enabled or disabled?

Did you check the config with btool?

0 Karma
Get Updates on the Splunk Community!

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...