Splunk Search

Saved Search Scheduling

Siddharthnegi
Contributor

I have a saved search which is scheduled but it is not showing and not running at the scheduled time.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

It's usually nice to actually ask a question after reporting the current state.

Typically if the search is properly defined and scheduled but is not being run, the issue is with resources. Are you sure your SH(C) is not overloaded and you have no delayed/skipped searches? Did you check scheduler's logs?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Siddharthnegi ,

is this savedsearch an alert or a report?

is this savedsearch shared at least at app level or private?

are you sure that the savedsearch has results?

please, make a test modifying the savedsearch assuting that there will be at least one result and see what happens.

Ciao.

Giuseppe 

0 Karma

Siddharthnegi
Contributor

Its a report , it is shared at global level, when i ran this search it is giving results.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Siddharthnegi ,

in the test, be sure that the time period is the same at the scheduled time.

Then, do you know in what app it's located?

so you can search it, if you don't know the app, you could search it on SSH in savedsearches.conf files.

Ciao.

Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Unlocking Unified Insights: New Gigamon Federated Search App for Splunk

In today’s data-heavy environment, organizations are caught in a data distribution dilemma. As data volumes ...

GA: New Data Management App in Splunk Platform

Streamlining Data Management: Introducing a unified experience in Splunk Managing data at scale shouldn’t feel ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...