Splunk Search

Is there setting to always enable auto_pause option?

yutaka1005
Builder

In 2010, the following Answers refered that there isn't a setting to always enable the auto_pause option, and that it is necessary to put this setting value in the URL every time.

https://answers.splunk.com/answers/3691/auto-pause-search-settings.html

Is this still correct today?
Or is there setting to always activate?

0 Karma

koshyk
Super Champion

You can do this, in case of a savedsearch. Please refer the doc https://docs.splunk.com/Documentation/Splunk/7.2.6/Admin/Savedsearchesconf

dispatch.auto_pause = <int>
* If specified, the search job pauses after this many seconds of inactivity. (0
  means never auto-pause.)
* To restart a paused search job, specify unpause as an action to POST
  search/jobs/{search_id}/control.
* auto_pause only goes into effect once. Unpausing after auto_pause does not
  put auto_pause into effect again.
* Default is 0.

I'm not sure your exactly whether you want to do at user level or Role level. Hope it helps

0 Karma

yutaka1005
Builder

Thank you for answer.

But I don't think that it is way that I'm searching.

0 Karma

deepashri_123
Motivator

Hey@yutaka1005,

Please refer this doc if u find something relevant.
https://docs.splunk.com/Documentation/Splunk/7.2.6/AdvancedDev/TurnOffAutoPause

Let me know if this helps!!

0 Karma

yutaka1005
Builder

Thank you for comment!

But I want to use this function in normal search page, not in simpleXML.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...