Splunk Search

How to catch information from inspector job?

jip31
Motivator

Hi

I would like to catch the information in the example below:

This search has completed and has returned 1 000 résultat by scanning 2 610 582 événement in 220,758 seconds

These information comes from the job inspector.
How can I catch information and the response time?

Thanks a lot

Tags (1)
0 Karma
1 Solution

harsmarvania57
Ultra Champion

Hi,

You can access these details in _audit index. If you have access to _audit index then try to run search index=_audit search_id=* info=completed this will provide run time, event count, result count etc.

View solution in original post

0 Karma

harsmarvania57
Ultra Champion

Hi,

You can access these details in _audit index. If you have access to _audit index then try to run search index=_audit search_id=* info=completed this will provide run time, event count, result count etc.

0 Karma

jip31
Motivator

thanks a lot

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Word Search

This challenge was first posted on Slack #puzzles channelThis puzzle is based on a letter grid containing ...

[Puzzles] Solve, Learn, Repeat: Advent of Code - Day 4

Advent of CodeIn order to participate in these challenges, you will need to register with the Advent of Code ...

GA: S3 Promote for Historical Data Ingestion in Splunk Cloud

Ingest Historical S3 Data On-Demand: Announcing the General Availability of S3 Promote We’re excited to share ...