Splunk Dev

How is the Auto Window being calculated?

danielbb
Motivator

We are not clear how the Auto Window is being calculated.

At Making the Most of the Splunk Scheduler

We see -

alt text

How exactly this auto window is being calculated?

Tags (1)

richgalloway
SplunkTrust
SplunkTrust

You are correct. A scheduled search needs a history before Splunk can set an auto window.

---
If this reply helps you, Karma would be appreciated.

danielbb
Motivator

The way I read it -

Let's say the Period (P) is 5 minutes, Runtime (R) is 2 minutes, then Window (W) would be 5 - 2 = 3.
Meaning, anytime within these 3 minutes, can be used by the scheduler to start the search.

I guess R is derived from pervious runs.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...