Splunk Enterprise

Why is this scheduled search not return results?

jip31
Motivator

Hi

In my dashboard, I use a search with 2 different ways

1) a inline search which works fine

2) a scheduled search which is exactly the same that the inline search but which returns any results even if the search ended correctly !

NB : this search was returning results at the beginning so it's very strange

I dont know if it's important but when I have a look at the job inspector I have the message below :

 

 

info : [subsearch]: Your timerange was substituted based on your search string

 

 

and what is even stranger is that when I run the search apart (it means outside the dashboard) I have also no results!

how is it possible please?

thanks

 

Labels (1)
Tags (1)
0 Karma
1 Solution

jip31
Motivator

I have found

it was due to the dispatch.earliest_time and dispatch.latest_time parameters

View solution in original post

0 Karma

jip31
Motivator

😀I am sure the issue dont comes directly from the search...

It was working a few days ago

how the same search works inline the dashboard and dont works outside the dashboard even if I dont use the scheduled search?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

OK, that's a little bit more information but still not enough for us to provide any meaningful assistance.

0 Karma

jip31
Motivator

I have found

it was due to the dispatch.earliest_time and dispatch.latest_time parameters

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

My guess is that line 3 of your search is wrong - anyone else for the sweepstake?

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...