Splunk Search

How to generate a search to identify scheduled jobs by user?

vadlamudi
Explorer

hi,

Can anyone please help me with a search to to identify scheduled jobs for abc and xyz application and the user owning that job? i know i need to use index=_internal and source=scheduler.log. But i am not getting the exact requirement that i need.

0 Karma

vasanthmss
Motivator

Check this,

https://answers.splunk.com/answers/494555/is-there-any-way-to-list-all-the-saved-searches-in-1.html#...

check the below query

| rest /services/saved/searches | where is_scheduled=1 

for historical scheduled searches use the below query,

index=_internal sourcetype=scheduler  | table _time user savedsearch_name status scheduled_time run_time result_count *
V
0 Karma
Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...