Splunk Search
Highlighted

Is there a difference between guided and manual mode? Is there a difference between real-time and continuous?

New Member

Guided and Manual Mode?

Real Time and Continuous?

Is one more efficient then the other?

Thank you.

Frank

0 Karma
Highlighted

Re: Is there a difference between guided and manual mode? Is there a difference between real-time and continuous?

Splunk Employee
Splunk Employee

Hey @frizzoS3, this can be read in docs:
Correlation searches can run with a real-time or continuous schedule.
• Use a real-time schedule to prioritize current data and performance. Searches with a real-time schedule are skipped if the search cannot be run at the scheduled time. Searches with a real-time schedule do not backfill gaps in data that occur if the search is skipped.
• Use a continuous schedule to prioritize data completion, as searches with a continuous schedule are never skipped.
As for guided vs. manual mode -- I think this is the difference, "Select a mode of Guided to create a search without having to write the search syntax yourself, or select Manual to write your own search."

Highlighted

Re: Is there a difference between guided and manual mode? Is there a difference between real-time and continuous?

New Member

Hi

I am trying to change the Scheduling on a correlation search to Continuous from Real Time, and I am getting a field " Fields to Group by" in order to save the search.

I have entered a couple of different field names, but to no avail as I keep getting the following message...."There was an error saving the correlation search."

Any suggestions?

Thank you

Frank

0 Karma