I have a savedsearches.conf deployed via a TA on Splunk. The conf has ~90-100 searches in it.
I would like to count the number of events generated per search query over a given period of time.
Could someone kindly help me with a Splunk query to do this? I've been trying for a while now.
index=_internal sourcetype=scheduler app="TA_name" | table _time user app savedsearch_name status scheduled_time run_time result_count
If this reply helps you, an upvote/like would be appreciated.
Hi thanks. Unfortunately the result_count which is the most important field for me returns 0 for all. Even though the searches have run.
I am getting proper values (not 0s) in the result_count. Check if your scheduled searches producing results in the Job Manager. Sometimes scheduled searches won't gives results due to incorrect time ranges, permissions to user running them etc.