Splunk Enterprise

Scheduled search with only | inputlookup in the search returns zero results

SteveBowser
Explorer

I created a scheduled search that reads 2 input lookup csv files. It returns zero results when I look at the "View Recent"/Job Manager. When I run it by clicking the "Run" selection, I get the results that I'm looking for. What am I overlooking? 

Labels (2)
0 Karma

SteveBowser
Explorer

Answering my own question here - it needs to have dates to display results. In the end, I wrote the results to a summary index in a scheduled search using | collect index=test_summary addtime=true. 

0 Karma

SteveBowser
Explorer

There are no timestamps in the lookup table. When I plug one in, I get the desired results. 

 

0 Karma

SteveBowser
Explorer

Sorry, I have access to the files.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Which user does the scheduled search run as and do they have access to the lookup files?

0 Karma

SteveBowser
Explorer

It's under my username, with Admin privileges.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...