Splunk Search

Can we force a query to launch first?

Gonzalo
Engager

Hello, I am new to splunk, I have no idea, and I am asking for your help, this is my question:
Can we force a query to launch first?

it would be launching the query: |rest /servicesXY/-/-/saved/searches timeout=0 before the rest.

I thank you very much for your time and help.

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please tell us more about your use case.  When is the query launching?  If this query must be first, what is expected to follow?  Why is the sequence important?

---
If this reply helps you, Karma would be appreciated.
0 Karma

Gonzalo
Engager

When this query is launched after others, it does not end well, that is, it ends due to timeout, and I have been given the task of searching for that query to be launched first.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I still don't understand this use case.  Splunk queries run continuously so, other than right after Splunk starts, there is no concept of a "first" query.  Searches can be scheduled in a manner that allows some to run before others, however.  Is that what you need?  If so, it's a matter of setting the schedules such that the "first" query runs at, say, 0100, and the others run some time later (allowing time for the first to complete). perhaps at 0130.

There is no other mechanism, however, to specify search "foo" must run before search "bar" or that search "bar" cannot run before search "foo".

---
If this reply helps you, Karma would be appreciated.

Gonzalo
Engager

Thank you very much for your answer, I will see it.

0 Karma
Get Updates on the Splunk Community!

What's New in Splunk Observability - October 2025

What’s New?  We’re excited to announce the latest enhancements to Splunk Observability Cloud and share what’s ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened Audit Trail v2 wasn’t written in isolation—it was shaped by your voices. In ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...