- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Workload Rule but it doesn't work
Zarack
Engager
01-12-2024
11:22 AM
I have configured a Workload Rule but it doesn't work, I need all searches that last more than 3 minutes and are not from sc_admin to stop. I tested it in the laboratory and it worked, is there something wrong with my rule?
(search_type=adhoc) AND NOT (role=sc_admin) AND runtime>3m
Remember that I did a lab and the same rule worked.
Splunk Instance version: 9.0.2305.201
Laboratory: 9.1.2308.102
Can you help me please.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
01-12-2024
12:23 PM
Make sure WLM is enabled and that there are no other rules with a higher priority that prevent this rule from executing.
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Zarack
Engager
01-18-2024
11:46 AM
Unfortunately it doesn't work, I configured the same rules in a working instance and it works.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
dural_yyz
Motivator
01-18-2024
12:36 PM
Have you checked the _audit logs to confirm user and roles values?
