I have a scheduled saved search that just calls a dbxoutput. When I run it manually, it finishes in a few minutes. When I schedule it to run, however, it takes 6 hours.
What logs/places should I check to try to find out why this is happening?
You can find info about scheduled searches in
index=_internal sourcetype=scheduler savedsearch_name=yoursearchname
look at things like scheduledtime,dispatch time, run time, status
View solution in original post
Check to see whether you've supplied a timerange in the scheduled search. This a common mistake -- missing timerange. Without a timerange Splunk attempts to run the search across "All Time".