Splunk Search

save search results?

jlawsonmers
New Member

Once a search has been created and saved, how does one change the amount of time (number of days, for example) that the results are saved?

Tags (1)
0 Karma

lguinn2
Legend

Look at this answer: Schedule Saved Search Retention which tells you to set

dispatch.ttl = <integer>[p] in the config file savedsearches.conf

However, this will only affect subsequent runs of the saved search. If you want to change the retention of a search that has already been run, you can "save" the search results. This means that the results will never expire, so you will have to manually delete the results when you don't want them any longer.

0 Karma

lguinn2
Legend

If it isn't there, then Splunk is using the default. So just add the line and see what happens!

0 Karma

jlawsonmers
New Member

In savedsearches.conf, I do not see dispatch.ttl. I do see dispatch.earliest_time and dispatch.latest_time, but these seem to refer to the scope of the search, not the retention of search results. Any other ideas?

0 Karma

jlawsonmers
New Member

No, somesoni2, the search parameters are ok. I'm talking about changing how long the search results are saved.

0 Karma

somesoni2
Revered Legend

Are you talking about the change in the earliest and latest parameter for saved search??

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...

Share Your Feedback: On Admin Config Service (ACS)!

Help Us Build a Better Admin Config Service Experience (ACS)   We Want Your Feedback on Admin Config Service ...

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...