I have a saved search pushed to my splunk app.
The search only gives me partial events searched (9k events ), where as when the saved search it in "search and reporting" app i get the complete results. (6000k events)
My savedsearch.conf inside my app directory
"/opt/splunk/etc/apps/My_APP/local/savedsearches.conf"
[My_SavedSearch]
cron_schedule = 0 0 * * *
dispatch.earliest_time = -7y@y
dispatch.index_earliest = -7y@y
dispatch.index_latest = now
enableSched = 1
run_on_startup = 1
dispatch.max_count = 500000000
search = | pivot Authentication Authentication count(Authentication) AS totalcount SPLITROW sourcetype AS sourcetype SORT 100 sourcetype ROWSUMMARY 0 COLSUMMARY 0 SHOWOTHER 1 | eval modelname="Authentication"
Hi
have you look what job inspector has said about those jobs? That could give some hints to us.
r. Ismo