Splunk Search

Savedsearch - alternative to CRON job?

GregSmith
Explorer

I have a savedsearch running on a 5 minute cron schedule iteratively working through a list of previously saved search parameters.

2 Things

(1) Can I have a conditional CRON schedule such that I somehow detect when work needs to be performed and if so, enable the CRON? The processing for a day may take 6 hours, but the CRON keeps running and burning resources.

(2) Some of the savedsearches run in < 1 min but others take longer than 5 minutes. Instead of using a CRON schedule, can I detect the savedsearch ID, detect when it has completed and then initiate the subsequent execution of the savedsearch on the next batch of data?  

Labels (1)
Tags (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

1) Cron runs continuously.  There's no way to change that.  Checking whether it's time to run a cron job is likely to be far less resource-intensive than checking if work needs to be performed.

2) You may be able to use the Splunk SDK/API to detect when a search completes and then trigger a subsequent search.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

1) Cron runs continuously.  There's no way to change that.  Checking whether it's time to run a cron job is likely to be far less resource-intensive than checking if work needs to be performed.

2) You may be able to use the Splunk SDK/API to detect when a search completes and then trigger a subsequent search.

---
If this reply helps you, Karma would be appreciated.
0 Karma

GregSmith
Explorer

Thank you Rich. Good pointers. When I come up for air, I will pursue the SDK/API path. 

Get Updates on the Splunk Community!

Splunk Lantern | Getting Started with Edge Processor, Machine Learning Toolkit ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...