Splunk Cloud Platform

Workload Rule but it doesn't work

Zarack
Engager

I have configured a Workload Rule but it doesn't work, I need all searches that last more than 3 minutes and are not from sc_admin to stop. I tested it in the laboratory and it worked, is there something wrong with my rule?
(search_type=adhoc) AND NOT (role=sc_admin) AND runtime>3m
Remember that I did a lab and the same rule worked.
Splunk Instance version: 9.0.2305.201
Laboratory: 9.1.2308.102

Can you help me please.

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Make sure WLM is enabled and that there are no other rules with a higher priority that prevent this rule from executing.

---
If this reply helps you, Karma would be appreciated.
0 Karma

Zarack
Engager

Unfortunately it doesn't work, I configured the same rules in a working instance and it works.

Zarack_0-1705607273215.png

 

 




0 Karma

dural_yyz
Communicator

Have you checked the _audit logs to confirm user and roles values?

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...