Splunk Search

Is this a scheduled real-time search?

a212830
Champion

Hi,

Are processes that contain "rt_scheduler" real-time scheduled searches?

Example:

splunk 15005 75443 0 10:20 ? 00:00:00 [splunkd pid=75442] search --id=remote_azone567_rt_scheduler_Z527062gns_BillPay_at_1459002000_14090 --maxbuckets=0 --ttl=60 --maxout=0 --maxtime=0 --lookups=1 --streaming --outCsv=true --user=username_removed_for_answers_post --pro --roles=dbx_user:power:user

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Should be. To be certain, search index=_audit for that search ID and look for the oldest event, it should contain lots of info about the search.

0 Karma

sloshburch
Ultra Champion

I wonder if you can also check the search activity or jobs list to see the corresponding search and view what actually was run.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Yeah, but that's only visible for as long as the job artefacts exist.

0 Karma
Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...