Splunk Search

How to abort a search if lookup file is causing errors and incomplete results?

ddelmont
Explorer

Hello all,

I'm using a search that baselines user activity (looks back in time). But I've noticed that sometimes the results are incomplete, and this messes with the next search in the pipeline.

Does anyone know how to "abort" (and not update) the lookup file if any errors occurred during the search? Thanks so much.

alt text

Labels (1)
0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!