Hi I would like to ask why is the Splunk Realtime Savesearch still running even it's expired.
Also whats the purpose of the Expiration time (24hrs) on the settings if it still runs ?
Yeah also formulate this for others:
Splunk Realtime adhoc and savesearches doesn’t end, since they are configured to gather the latest data on a Realtime manner.
Ex. If I ran adhoc search with 5min Realtime . It wont end, complete or fail (on a normal circumstances), it will just continue until I stop the search.
“Expires” configuration on the settings doesn’t really affect the real time search runtime – it only applies on cron job savesearches output.
“Expires” is the time that the output of the search will remain on the Splunk environment.
Solution to this issue is to adjust the real time configuration to a cron job that is “almost realtime” (2min,5min or 10min). In this way searches will not queue up and still get the latest output. Also, to refrain using real-time searches.