Security

Splunk capability Explanation

shaun_dyble
Explorer

Can someone please explain the difference between :

  • schedule_rtsearch
  • rtsearch
  • schedule_search

Does schedule_rtsearch give the user the ability to create scheduled searches that use real time? And if that ability was taken away , but the same user still had rtseach and schedule_search, would they still be able to create a scheduled search that uses real time?

0 Karma

shaun_dyble
Explorer

So if a user has all 3, and schedule_rtsearch is removed, they can still schedule real time searches?

0 Karma

musskopf
Builder

Have a look here: http://dev.splunk.com/view/python-sdk/SP-CAAAEJ6

The use needs multiple capabilities to schedule a RT search

0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...