Splunk Search

Is there a difference between guided and manual mode? Is there a difference between real-time and continuous?

frizzoS3
New Member

Guided and Manual Mode?

Real Time and Continuous?

Is one more efficient then the other?

Thank you.

Frank

0 Karma

lfedak_splunk
Splunk Employee
Splunk Employee

Hey @frizzoS3, this can be read in docs:
Correlation searches can run with a real-time or continuous schedule.
• Use a real-time schedule to prioritize current data and performance. Searches with a real-time schedule are skipped if the search cannot be run at the scheduled time. Searches with a real-time schedule do not backfill gaps in data that occur if the search is skipped.
• Use a continuous schedule to prioritize data completion, as searches with a continuous schedule are never skipped.
As for guided vs. manual mode -- I think this is the difference, "Select a mode of Guided to create a search without having to write the search syntax yourself, or select Manual to write your own search."

frizzoS3
New Member

Hi

I am trying to change the Scheduling on a correlation search to Continuous from Real Time, and I am getting a field " Fields to Group by" in order to save the search.

I have entered a couple of different field names, but to no avail as I keep getting the following message...."There was an error saving the correlation search."

Any suggestions?

Thank you

Frank

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...