Reporting

What happened to logging of my scheduled searches (by name) in version 4.0?

the_wolverine
Champion
INFO  SavedSplunker - Found 2 scheduled saved searches
INFO  SavedSplunker - About to run saved search: 'admin;search;badger', next run: Thu Apr 29 12:43:00 2010, trigger_actions=1
INFO  SavedSplunker - setting ttl=120 for savedsearch_ident="admin;search;badger"
INFO  SavedSplunker - dispatched search for savedsearch_id="admin;search;badger"
INFO  SavedSplunker - Saved search 'admin;search;badger' next run time set to: "Thu Apr 29 12:44:00 2010"
INFO  SavedSplunker - changing ttl of sid=scheduler_admin_search_badger_at_1272570180_1230566965, new_ttl=86400
INFO  SavedSplunker - AlertNotifier ran notifications=1, actions=1, managedSearchCount=0

It used to be that I could see my scheduled search runs in splunkd.log like above. This was very useful for debugging. What happened to them?

0 Karma
1 Solution

the_wolverine
Champion

SavedSplunker errors were converted to WARN in later versions of 4.0. You can re-enable logging at the INFO level by adding the following to your etc/log.cfg under [splunkd]:

[splunkd]
category.SavedSplunker=INFO

If you've got lots of scheduled searches this will result in a noisy splunkd.log.

In 4.1 we change the default logging to INFO and give it its own logfile: scheduler.log.

View solution in original post

0 Karma

the_wolverine
Champion

SavedSplunker errors were converted to WARN in later versions of 4.0. You can re-enable logging at the INFO level by adding the following to your etc/log.cfg under [splunkd]:

[splunkd]
category.SavedSplunker=INFO

If you've got lots of scheduled searches this will result in a noisy splunkd.log.

In 4.1 we change the default logging to INFO and give it its own logfile: scheduler.log.

0 Karma
Get Updates on the Splunk Community!

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...

Explore the Latest Educational Offerings from Splunk [January 2025 Updates]

At Splunk Education, we are committed to providing a robust learning experience for all users, regardless of ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...