Splunk Search

Saved Search Scheduling

Siddharthnegi
Contributor

I have a saved search which is scheduled but it is not showing and not running at the scheduled time.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

It's usually nice to actually ask a question after reporting the current state.

Typically if the search is properly defined and scheduled but is not being run, the issue is with resources. Are you sure your SH(C) is not overloaded and you have no delayed/skipped searches? Did you check scheduler's logs?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Siddharthnegi ,

is this savedsearch an alert or a report?

is this savedsearch shared at least at app level or private?

are you sure that the savedsearch has results?

please, make a test modifying the savedsearch assuting that there will be at least one result and see what happens.

Ciao.

Giuseppe 

0 Karma

Siddharthnegi
Contributor

Its a report , it is shared at global level, when i ran this search it is giving results.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Siddharthnegi ,

in the test, be sure that the time period is the same at the scheduled time.

Then, do you know in what app it's located?

so you can search it, if you don't know the app, you could search it on SSH in savedsearches.conf files.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...