Splunk Search

How to catch information from inspector job?

jip31
Motivator

Hi

I would like to catch the information in the example below:

This search has completed and has returned 1 000 résultat by scanning 2 610 582 événement in 220,758 seconds

These information comes from the job inspector.
How can I catch information and the response time?

Thanks a lot

Tags (1)
0 Karma
1 Solution

harsmarvania57
Ultra Champion

Hi,

You can access these details in _audit index. If you have access to _audit index then try to run search index=_audit search_id=* info=completed this will provide run time, event count, result count etc.

View solution in original post

0 Karma

harsmarvania57
Ultra Champion

Hi,

You can access these details in _audit index. If you have access to _audit index then try to run search index=_audit search_id=* info=completed this will provide run time, event count, result count etc.

0 Karma

jip31
Motivator

thanks a lot

0 Karma
Get Updates on the Splunk Community!

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...

Federated Search for Amazon S3 | Key Use Cases to Streamline Compliance Workflows

Modern business operations are supported by data compliance. As regulations evolve, organizations must ...