Splunk Search

Splunk savesearch expires but still running

jadengoho
Builder

Hi I would like to ask why is the Splunk Realtime Savesearch still running even it's expired.

jadengoho_1-1593600886218.png

 

Also whats the purpose of the Expiration time (24hrs) on the settings if it still runs ?

 

Labels (1)
Tags (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust
Real-time searches run forever or until they are explicitly stopped. The results, however, will expire after 24 hours.
---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust
Real-time searches run forever or until they are explicitly stopped. The results, however, will expire after 24 hours.
---
If this reply helps you, Karma would be appreciated.
0 Karma

jadengoho
Builder

Yeah also formulate this for others:

Splunk Realtime adhoc and savesearches  doesn’t end, since they are configured to gather the latest data on a Realtime manner.

                Ex. If I ran  adhoc search with 5min Realtime . It wont end, complete or fail (on a normal circumstances), it will just continue until I stop the search.

“Expires” configuration on the settings doesn’t really affect the real time search runtime – it only applies on cron job savesearches output.

“Expires” is the time that the output of the search will remain on the Splunk environment.

Solution to this issue is  to adjust the real time configuration to a cron job that is “almost realtime” (2min,5min or 10min). In this way searches will not queue up and still get the latest output. Also, to refrain using real-time searches.

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...