Splunk Search

What is Naming convention for files in dispatch folder?

richnavis
Contributor

From time to time, I would need to blast the folders in the dispatch folder. Can anyone shed some light on the naming convention? Here are the name prefixes I have found... Some are obvious, some... not so much...


scheduler
rt
remote
"somenumber"
splunk01
"username"

Tags (1)
0 Karma
1 Solution

n8
Splunk Employee
Splunk Employee

"somenumber" are the ad-hoc searches that a user kicks off. The number is the epoch timestamp.

http://blogs.splunk.com/2012/09/12/deciphering-dispatch-directory-names/

View solution in original post

n8
Splunk Employee
Splunk Employee

"somenumber" are the ad-hoc searches that a user kicks off. The number is the epoch timestamp.

http://blogs.splunk.com/2012/09/12/deciphering-dispatch-directory-names/

richnavis
Contributor

Ok.. gonna answer some of this myself based on observation in my environment...


1. scheduler--this search has been invoked by the scheduler... duh!

2. rt--searches that are real time

3. remote-In a pooled search head environment, the search is dispatched for all pooled search heads, so, searches with the "Remote" prefix essentially indicates that the search is a spawned to a searchhead from the original search.

4. somenumber--haven't figured this one out yet.

5. Splunk01--this is a mistake.. there is no splunk prefix

6. username--this is a search spawned by a user

so.. just need to figure out what "somenumber" is.. then I'm good.. if anyone can help..that would be great.

0 Karma
Get Updates on the Splunk Community!

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Cultivate Your Career Growth with Fresh Splunk Training

Growth doesn’t just happen—it’s nurtured. Like tending a garden, developing your Splunk skills takes the right ...