Splunk Enterprise

Extend Job TTL Globally

tmontney
Builder

This article states how to change the TTL for a saved search individually: https://docs.splunk.com/Documentation/SplunkCloud/8.2.2105/Search/Extendjoblifetimes I want to change the default TTL of any and all saved searches. Otherwise, I and my team have to remember to change this for each new search we save.

Labels (1)
0 Karma

codebuilder
Influencer

You can accomplish this by adding a [default] stanza to savedsearches.conf and adding dispatch.ttl = your_value_here under it. Where your_value_here = time to live in seconds.

At the application level, Include the updated savedsearches.conf in $SPLUNK_HOME/etc/apps/<app_name>/local

For a system level change place savedsearches.conf at $SPLUNK_HOME/etc/system/local. Though this is NOT recommended.

Documentation is here under 'dispatch search options' :
https://docs.splunk.com/Documentation/DFS/1.1.2/DFS/Savedsearchesconf

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma

codebuilder
Influencer

Also, if you do add dispatch.ttl to a [default] stanza, then you would need to remove that setting from individual search stanzas as those would override what's in default.

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma
Get Updates on the Splunk Community!

SOC Modernization: How Automation and Splunk SOAR are Shaping the Next-Gen Security ...

Security automation is no longer a luxury but a necessity. Join us to learn how Splunk ES and SOAR empower ...

Ask It, Fix It: Faster Investigations with AI Assistant in Observability Cloud

  Join us in this Tech Talk and learn about the recently launched AI Assistant in Observability Cloud. With ...

Index This | How many sides does a circle have?

  March 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...