Splunk Search

Facing issues when scheduling the saved search

srinivas_gowda
Path Finder

Hello all,

I have a saved search that I want to run once every Sunday at 00:00. I have added in the query to pick the events for the last 7 days as: earliest=-7d@d latest=@m.

I have also scheduled it to run every week on Sunday at 00:00 and time range as Last 7 Days.

 

When I run the saved search manually it is working as expected and also when I run this by changing the schedule to run every 5 mins for last 7 days range it is able to index the data. However, when I schedule it to run once every week, even though the search is running the data is not being indexed to tier3. When I checked the job manager, the run was successfully completed but no data was pushed to tier3.

 

Can you please help on this.

Labels (2)
0 Karma

burwell
SplunkTrust
SplunkTrust

Hi. I am not understanding the difference between the two searches.

Can you share the exact settings in the saved search for the time?

In case you have a personalized time setting to show you events in some specific time zone ( eg your events are in UTC but you want to see the time in terms of EST) you should know that the scheduled job times are with respect to this time zone setting of the user is the scheduled job.

 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...