Splunk Enterprise

Why is Savedsearch giving only partial results?

analysthok
Loves-to-Learn Lots

 

I have a saved search pushed to my splunk app.

The search only gives me partial events searched (9k events ), where as when the saved search it in "search and reporting" app i get the complete results. (6000k events)

 

My savedsearch.conf inside my app directory 
"/opt/splunk/etc/apps/My_APP/local/savedsearches.conf"

 

 

[My_SavedSearch]
cron_schedule = 0 0 * * *
dispatch.earliest_time = -7y@y
dispatch.index_earliest = -7y@y
dispatch.index_latest = now
enableSched = 1
run_on_startup = 1
dispatch.max_count = 500000000
search = | pivot Authentication Authentication count(Authentication) AS totalcount SPLITROW sourcetype AS sourcetype SORT 100 sourcetype ROWSUMMARY 0 COLSUMMARY 0 SHOWOTHER 1 | eval modelname="Authentication"

 

 

My splunk app - savedsearchMy splunk app - savedsearch

 

savedsearch in search appsavedsearch in search app

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

have you look what job inspector has said about those jobs? That could give some hints to us.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...