Splunk Search

Splunk savesearch expires but still running

jadengoho
Builder

Hi I would like to ask why is the Splunk Realtime Savesearch still running even it's expired.

jadengoho_1-1593600886218.png

 

Also whats the purpose of the Expiration time (24hrs) on the settings if it still runs ?

 

Labels (1)
Tags (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust
Real-time searches run forever or until they are explicitly stopped. The results, however, will expire after 24 hours.
---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust
Real-time searches run forever or until they are explicitly stopped. The results, however, will expire after 24 hours.
---
If this reply helps you, Karma would be appreciated.
0 Karma

jadengoho
Builder

Yeah also formulate this for others:

Splunk Realtime adhoc and savesearches  doesn’t end, since they are configured to gather the latest data on a Realtime manner.

                Ex. If I ran  adhoc search with 5min Realtime . It wont end, complete or fail (on a normal circumstances), it will just continue until I stop the search.

“Expires” configuration on the settings doesn’t really affect the real time search runtime – it only applies on cron job savesearches output.

“Expires” is the time that the output of the search will remain on the Splunk environment.

Solution to this issue is  to adjust the real time configuration to a cron job that is “almost realtime” (2min,5min or 10min). In this way searches will not queue up and still get the latest output. Also, to refrain using real-time searches.

Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...