Splunk Enterprise

Why is this scheduled search not return results?

jip31
Motivator

Hi

In my dashboard, I use a search with 2 different ways

1) a inline search which works fine

2) a scheduled search which is exactly the same that the inline search but which returns any results even if the search ended correctly !

NB : this search was returning results at the beginning so it's very strange

I dont know if it's important but when I have a look at the job inspector I have the message below :

 

 

info : [subsearch]: Your timerange was substituted based on your search string

 

 

and what is even stranger is that when I run the search apart (it means outside the dashboard) I have also no results!

how is it possible please?

thanks

 

Tags (1)
0 Karma
1 Solution

jip31
Motivator

I have found

it was due to the dispatch.earliest_time and dispatch.latest_time parameters

View solution in original post

0 Karma

jip31
Motivator

😀I am sure the issue dont comes directly from the search...

It was working a few days ago

how the same search works inline the dashboard and dont works outside the dashboard even if I dont use the scheduled search?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

OK, that's a little bit more information but still not enough for us to provide any meaningful assistance.

0 Karma

jip31
Motivator

I have found

it was due to the dispatch.earliest_time and dispatch.latest_time parameters

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

My guess is that line 3 of your search is wrong - anyone else for the sweepstake?

0 Karma
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...