I am running | rest /services/search/jobs command to check my failed searches for last 24 hrs. But I see that some of the searches are not getting captured. I wanted to know how long in past does rest command searches the data.
Does it bring up results only for last few hours or few days ?
Hi @nagar57
the /services/search/jobs gives the results jobs which are active , means searches which are not expried
Based on type of search run there is ttl(time to live ) value for search,
may be some searched are expired after TTL , so you are not able to view them,
alertnatly you can view from
My job expiry date is 7th Jan still this job is not getting captured with rest command.
Below is the query I am using :
| rest /services/search/jobs count=0 splunk_server=*
| search isDone=1 isSavedSearch=1 messages.error!="*requires a .csv or KV store lookup definition*"
| rename messages.error as message eai:acl.app as App_Name label as Splunk_Search
| table Date Time App_Name Splunk_Search splunk_server message
Also., I see that this job failure is getting captured in _internal logs. Don't know why rest command is not able to capture it.