Splunk Search

Savedsearch - alternative to CRON job?

GregSmith
Explorer

I have a savedsearch running on a 5 minute cron schedule iteratively working through a list of previously saved search parameters.

2 Things

(1) Can I have a conditional CRON schedule such that I somehow detect when work needs to be performed and if so, enable the CRON? The processing for a day may take 6 hours, but the CRON keeps running and burning resources.

(2) Some of the savedsearches run in < 1 min but others take longer than 5 minutes. Instead of using a CRON schedule, can I detect the savedsearch ID, detect when it has completed and then initiate the subsequent execution of the savedsearch on the next batch of data?  

Labels (1)
Tags (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

1) Cron runs continuously.  There's no way to change that.  Checking whether it's time to run a cron job is likely to be far less resource-intensive than checking if work needs to be performed.

2) You may be able to use the Splunk SDK/API to detect when a search completes and then trigger a subsequent search.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

1) Cron runs continuously.  There's no way to change that.  Checking whether it's time to run a cron job is likely to be far less resource-intensive than checking if work needs to be performed.

2) You may be able to use the Splunk SDK/API to detect when a search completes and then trigger a subsequent search.

---
If this reply helps you, Karma would be appreciated.
0 Karma

GregSmith
Explorer

Thank you Rich. Good pointers. When I come up for air, I will pursue the SDK/API path. 

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...