Splunk Search

Splunk savesearch expires but still running

jadengoho
Builder

Hi I would like to ask why is the Splunk Realtime Savesearch still running even it's expired.

jadengoho_1-1593600886218.png

 

Also whats the purpose of the Expiration time (24hrs) on the settings if it still runs ?

 

Tags (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust
Real-time searches run forever or until they are explicitly stopped. The results, however, will expire after 24 hours.
---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust
Real-time searches run forever or until they are explicitly stopped. The results, however, will expire after 24 hours.
---
If this reply helps you, Karma would be appreciated.
0 Karma

jadengoho
Builder

Yeah also formulate this for others:

Splunk Realtime adhoc and savesearches  doesn’t end, since they are configured to gather the latest data on a Realtime manner.

                Ex. If I ran  adhoc search with 5min Realtime . It wont end, complete or fail (on a normal circumstances), it will just continue until I stop the search.

“Expires” configuration on the settings doesn’t really affect the real time search runtime – it only applies on cron job savesearches output.

“Expires” is the time that the output of the search will remain on the Splunk environment.

Solution to this issue is  to adjust the real time configuration to a cron job that is “almost realtime” (2min,5min or 10min). In this way searches will not queue up and still get the latest output. Also, to refrain using real-time searches.

Get Updates on the Splunk Community!

New This Month - Splunk Observability updates and improvements for faster ...

What’s New? This month, we’re delivering several enhancements across Splunk Observability Cloud for faster and ...

What's New in Splunk Cloud Platform 9.3.2411?

Hey Splunky People! We are excited to share the latest updates in Splunk Cloud Platform 9.3.2411. This release ...

Buttercup Games: Further Dashboarding Techniques (Part 6)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...