Reporting

scheduled search doesn't get any events

sansri7680
Path Finder

Hi

I created a scheduled search with the below search string

sourcetype="MME_Reject-3" | eval indextime=_indextime | eval tnow=now() | eval diff=tnow-indextime | sort + diff | where diff<60 | reverse | table _raw | outputcsv 4G_REJECT_LOG.txt

The source is fed by a forwarder that forwards data from windows machine

The search brings results whenever it is force run but when it runs using the schedule of 1 minute it doesn't bring any result

Can someone throw light on what the problem could be. splunkd.log doesn't display any error

0 Karma
1 Solution

sansri7680
Path Finder

Found it out. The dispatch.ttl was the culprit. I changed it to 1 second and everything is fine now

View solution in original post

sansri7680
Path Finder

Found it out. The dispatch.ttl was the culprit. I changed it to 1 second and everything is fine now

Get Updates on the Splunk Community!

Splunk Community Platform Survey

Hey Splunk Community, Starting today, the community platform may prompt you to participate in a survey. The ...

Observability Highlights | November 2022 Newsletter

 November 2022Observability CloudEnd Of Support Extension for SignalFx Smart AgentSplunk is extending the End ...

Avoid Certificate Expiry Issues in Splunk Enterprise with Certificate Assist

This blog post is part 2 of 4 of a series on Splunk Assist. Click the links below to see the other ...