Splunk Enterprise

Scheduled search with only | inputlookup in the search returns zero results

SteveBowser
Explorer

I created a scheduled search that reads 2 input lookup csv files. It returns zero results when I look at the "View Recent"/Job Manager. When I run it by clicking the "Run" selection, I get the results that I'm looking for. What am I overlooking? 

Labels (2)
0 Karma

SteveBowser
Explorer

Answering my own question here - it needs to have dates to display results. In the end, I wrote the results to a summary index in a scheduled search using | collect index=test_summary addtime=true. 

0 Karma

SteveBowser
Explorer

There are no timestamps in the lookup table. When I plug one in, I get the desired results. 

 

0 Karma

SteveBowser
Explorer

Sorry, I have access to the files.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Which user does the scheduled search run as and do they have access to the lookup files?

0 Karma

SteveBowser
Explorer

It's under my username, with Admin privileges.

0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

  Ready to master Kubernetes and cloud monitoring like the pros?Join Splunk’s Growth Engineering team for an ...

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...