Splunk Search

How to generate a search to identify scheduled jobs by user?

vadlamudi
Explorer

hi,

Can anyone please help me with a search to to identify scheduled jobs for abc and xyz application and the user owning that job? i know i need to use index=_internal and source=scheduler.log. But i am not getting the exact requirement that i need.

0 Karma

vasanthmss
Motivator

Check this,

https://answers.splunk.com/answers/494555/is-there-any-way-to-list-all-the-saved-searches-in-1.html#...

check the below query

| rest /services/saved/searches | where is_scheduled=1 

for historical scheduled searches use the below query,

index=_internal sourcetype=scheduler  | table _time user savedsearch_name status scheduled_time run_time result_count *
V
0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...