Splunk Search

How do I set a query to run overnight without it expiring before it completes?

thisissplunk
Builder

I need to run a search that will take around 6-8 hours. Just a lot of URLs with wildcards to look for in a terabyte of access logs with two indexers.

It seems as though if I go AFK for over 30 minutes then the search freezes or the job expires when it was still searching. How do I prevent this so that I can let it run overnight?

Edit: For now I shared the job from the Job Manager and I think it extended its life for 7 days. Hopefully this does it...

0 Karma

harsmarvania57
Ultra Champion

Is this ad-hoc search or scheduled search? If it is scheduled search then what is the running frequency ? Worth to look at https://docs.splunk.com/Documentation/Splunk/7.0.1/Search/Extendjoblifetimes

0 Karma

mayurr98
Super Champion

Hey you can send the job to background
Have a look at this doc!
http://docs.splunk.com/Documentation/SplunkCloud/6.6.3/Search/Aboutjobsandjobmanagement#Job_menu

Once you do this you will get a link which you can access for 7 days

Let me know if this helps !

thisissplunk
Builder

Hmm I don't see that option anywhere. I shared the search instead and I think that did it.

0 Karma

mayurr98
Super Champion

After entering your query on the right side of the search bar below time picker you will see Job v click on that and you will see Send Job to Background option.

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...