Splunk Cloud Platform

Workload Rule but it doesn't work

Zarack
Engager

I have configured a Workload Rule but it doesn't work, I need all searches that last more than 3 minutes and are not from sc_admin to stop. I tested it in the laboratory and it worked, is there something wrong with my rule?
(search_type=adhoc) AND NOT (role=sc_admin) AND runtime>3m
Remember that I did a lab and the same rule worked.
Splunk Instance version: 9.0.2305.201
Laboratory: 9.1.2308.102

Can you help me please.

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Make sure WLM is enabled and that there are no other rules with a higher priority that prevent this rule from executing.

---
If this reply helps you, Karma would be appreciated.
0 Karma

Zarack
Engager

Unfortunately it doesn't work, I configured the same rules in a working instance and it works.

Zarack_0-1705607273215.png

 

 




0 Karma

dural_yyz
Contributor

Have you checked the _audit logs to confirm user and roles values?

0 Karma
Get Updates on the Splunk Community!

Let’s Talk Terraform

If you’re beyond the first-weeks-of-a-startup stage, chances are your application’s architecture is pretty ...

Cloud Platform | Customer Change Announcement: Email Notification is Available For ...

The Notification Team is migrating our email service provider. As the rollout progresses, Splunk has enabled ...

Save the Date: GovSummit Returns Wednesday, December 11th!

Hey there, Splunk Community! Exciting news: Splunk’s GovSummit 2024 is returning to Washington, D.C. on ...