Splunk Search

Saved Search ( Scheduled Report) in Simple XML Dashboard

madhav_dholakia
Contributor

Hello,

I am facing an issue when a saved report is used in a simple xml dashboard using 

| loadjob savedsearch="madhav.d@xyz.com:App_Support:All Calls"

 

My time zone preference is (GMT+01:00) Greenwich Mean Time : London and the report I am referring to (All Calls) is also created by me and runs every 15 mins.

Now, when I use this report in a simple xml dashboard, it only provided data as on an hour ago.

Example: when the report runs at 08:00 AM and I check dashboard at 08:05 AM, it will show report results for 07:00 AM run and not the latest.

I expect this to be due to recent day light saving time changes in UK. Can someone please help how should I handle this?

Thank you.

Regards,

Madhav

Labels (1)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @madhav_dholakia 

When you run the same loadjob in the SPL search bar at the same time as in the dashboard - do you get the same - old - results?

Does the scheduled search job you're loading have the earliest/latest fixed in the SPL or the search config? What is this set to?

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...