Splunk Search

Is there a difference between guided and manual mode? Is there a difference between real-time and continuous?

frizzoS3
New Member

Guided and Manual Mode?

Real Time and Continuous?

Is one more efficient then the other?

Thank you.

Frank

0 Karma

lfedak_splunk
Splunk Employee
Splunk Employee

Hey @frizzoS3, this can be read in docs:
Correlation searches can run with a real-time or continuous schedule.
• Use a real-time schedule to prioritize current data and performance. Searches with a real-time schedule are skipped if the search cannot be run at the scheduled time. Searches with a real-time schedule do not backfill gaps in data that occur if the search is skipped.
• Use a continuous schedule to prioritize data completion, as searches with a continuous schedule are never skipped.
As for guided vs. manual mode -- I think this is the difference, "Select a mode of Guided to create a search without having to write the search syntax yourself, or select Manual to write your own search."

frizzoS3
New Member

Hi

I am trying to change the Scheduling on a correlation search to Continuous from Real Time, and I am getting a field " Fields to Group by" in order to save the search.

I have entered a couple of different field names, but to no avail as I keep getting the following message...."There was an error saving the correlation search."

Any suggestions?

Thank you

Frank

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...