Splunk Search

How to use different time ranges in sub-queries in savedsearches.conf

isamrat
Explorer

I am using a composite query which has join to another query. I need to use a longer time range in the main/outer query and the inner query should have the time range from the dispatch.earliest_time defined in the savedsearches.conf.

Suppose I have the below configurations in savedsearches.conf

cron_schedule = 05,25,45 * * * *
dispatch.earliest_time = -25m@m
dispatch.latest_time = -5m@m
search=index=data_set earliest=-120m@m app= "demo" Status=SUCCESS | join FileName,FilesCount [ search index= data_set app=demo status_message= "not completed"| table FileName,FilesCount] | table FileName,FilesCount, status,_time

Will the above config work?

The below query need to be run for last 2 hours:

index=data_set app= "demo" Status=SUCCESS

The below query need to be run for the savedsearches.conf configurations:

index= data_set app=demo status_message= "not completed" | table FileName,FilesCount

The query can not be changed. Please help me to do this.

0 Karma
1 Solution

somesoni2
Revered Legend

This setup will work fine. The explicit timerange in the base search would override the timerange you set for your saved search (the dispatch.*_time values), but it would get applied to subsearch.

View solution in original post

somesoni2
Revered Legend

This setup will work fine. The explicit timerange in the base search would override the timerange you set for your saved search (the dispatch.*_time values), but it would get applied to subsearch.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...