Reporting

How can I determine the lag between when an app's scheduled search is supposed to run and when it actually runs?

nnmiller
Contributor

Our scheduled searches seem to be lagging behind. I need a search to identify the delay between the scheduled time and the actual run time.

1 Solution

nnmiller
Contributor
index=_internal (host=) sourcetype=scheduler app= scheduled_time=* 
| eval time=strftime(_time,"%Y-%m-%d %H:%M:%S") | eval delay_in_start = (dispatch_time - scheduled_time) 
| eval scheduled_time=strftime(scheduled_time,"%Y-%m-%d %H:%M:%S") 
| eval dispatch_time=strftime(dispatch_time,"%Y-%m-%d %H:%M:%S") 
| table savedsearch_name,delay_in_start, scheduled_time, dispatch_time, time, run_time, status

Replace search_head_hostname with your search head name or IP address, replace app with the name of an app or remove it for all scheduled searches.

Hat tip: A very clueful customer

View solution in original post

nnmiller
Contributor
index=_internal (host=) sourcetype=scheduler app= scheduled_time=* 
| eval time=strftime(_time,"%Y-%m-%d %H:%M:%S") | eval delay_in_start = (dispatch_time - scheduled_time) 
| eval scheduled_time=strftime(scheduled_time,"%Y-%m-%d %H:%M:%S") 
| eval dispatch_time=strftime(dispatch_time,"%Y-%m-%d %H:%M:%S") 
| table savedsearch_name,delay_in_start, scheduled_time, dispatch_time, time, run_time, status

Replace search_head_hostname with your search head name or IP address, replace app with the name of an app or remove it for all scheduled searches.

Hat tip: A very clueful customer

RicoSuave
Builder

OHS MAIS GAWDS! IS EXACTLIES GUATS I GUAS LEWKANS FOUR! JEW HLEPS ME FIINDS THESE LAGERS IN MAI ENVIRONMENTS!

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...