Splunk Search

where are job manager search results stored

jonathanfalconi
Explorer

Hi - Where are the job manager search results stored on the disk if I want to find it via CLI?

Tags (2)
0 Karma

Jason
Motivator

If you need to know where a particular search result is, use a REST search.

| rest splunk_server=local count=0 /services/search/jobs | rename title as searchString | rename label as searchName | table searchName searchString sid | search searchName="...etc"

This will get you a transposed (fields are now events) listing of the newest search job. 'sid' is the Search ID, and also the name of the folder in your dispatch directory.

0 Karma

sowings
Splunk Employee
Splunk Employee

Job results are stored in the dispatch directory on the search head: $SPLUNK_HOME/var/run/splunk/dispatch.

splunker12er
Motivator

Location : dispatch directory
Default storage period : 7 days (later it will be deleted)

0 Karma

sowings
Splunk Employee
Splunk Employee

The SID should match the name of the directory in there. I just ran a search, used the job inspector to find the SID: 1380118161.133, and sure enough, there's a directory by that name in the dispatch directory. Any others you see in there with a longer form, such as: scheduler__nobody__SplunkforPaloAltoNetworks__RMD548bd043d4f751080_at\_1380118200_27537 represent scheduled jobs.

0 Karma

jonathanfalconi
Explorer

Thanks - there are quite a few folders in dispatch dir, how can I work out where my particular job is? I do have the SID.

0 Karma
Get Updates on the Splunk Community!

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability As businesses scale ...