Splunk Search

Splunk savesearch expires but still running

jadengoho
Builder

Hi I would like to ask why is the Splunk Realtime Savesearch still running even it's expired.

jadengoho_1-1593600886218.png

 

Also whats the purpose of the Expiration time (24hrs) on the settings if it still runs ?

 

Labels (1)
Tags (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust
Real-time searches run forever or until they are explicitly stopped. The results, however, will expire after 24 hours.
---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust
Real-time searches run forever or until they are explicitly stopped. The results, however, will expire after 24 hours.
---
If this reply helps you, Karma would be appreciated.
0 Karma

jadengoho
Builder

Yeah also formulate this for others:

Splunk Realtime adhoc and savesearches  doesn’t end, since they are configured to gather the latest data on a Realtime manner.

                Ex. If I ran  adhoc search with 5min Realtime . It wont end, complete or fail (on a normal circumstances), it will just continue until I stop the search.

“Expires” configuration on the settings doesn’t really affect the real time search runtime – it only applies on cron job savesearches output.

“Expires” is the time that the output of the search will remain on the Splunk environment.

Solution to this issue is  to adjust the real time configuration to a cron job that is “almost realtime” (2min,5min or 10min). In this way searches will not queue up and still get the latest output. Also, to refrain using real-time searches.

Get Updates on the Splunk Community!

Admin Your Splunk Cloud, Your Way

Join us to maximize different techniques to best tune Splunk Cloud. In this Tech Enablement, you will get ...

Cloud Platform | Discontinuing support for TLS version 1.0 and 1.1

Overview Transport Layer Security (TLS) is a security communications protocol that lets two computers, ...

New Customer Testimonials

Enterprises of all sizes and across different industries are accelerating cloud adoption by migrating ...