Other Usage

Is there a way to set the job TTL to a different value for a saved search?

bohrasaurabh
Communicator

Is there a way to set the job ttl to a different value for a saved search?

woodcock
Esteemed Legend

You can also use "| noop set_ttl = <NumberOfSecondsHere>"

0 Karma

guilmxm
Influencer

bohrasaurabh gave you the answer, edit your search (in savedsearches.conf) As a line like:

dispatch.ttl = 3600

Note that the time is in seconds

bhawkins1
Communicator

Note that you can also specify the value as [0-9]+p, e.g. dispatch.ttl = 7p - this means "save 7 versions of the saved search".

You can then use old searches with, for example | loadjob savedsearch="x:y:z" artifact_offset=3

0 Karma

somesoni2
Revered Legend
0 Karma

bohrasaurabh
Communicator

dispatch.ttl for savedsearch is different from jobs ttl. my understanding is jobs ttl defines how long the job will be in jobs activity.

0 Karma

risgupta_splunk
Splunk Employee
Splunk Employee

Yes, the TTL setting for the alert overrides the setting in savedsearches.conf, but you should set the TTL in both places. The TTL in alert_actions.conf only applies if an alert is triggered, otherwise the TTL in savedsearches.conf applies.

In both places, you can use the p notation or just the number of seconds to save.

There are also settings for TTL in limits.conf, but those only apply to ad hoc searches.

0 Karma

somesoni2
Revered Legend

I guess you can update savedsearches.conf file for that saved search and set the dispatch.ttl to your configured value. Is that what you're looking for?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...