Splunk Search

where are job manager search results stored

jonathanfalconi
Explorer

Hi - Where are the job manager search results stored on the disk if I want to find it via CLI?

Tags (2)
0 Karma

Jason
Motivator

If you need to know where a particular search result is, use a REST search.

| rest splunk_server=local count=0 /services/search/jobs | rename title as searchString | rename label as searchName | table searchName searchString sid | search searchName="...etc"

This will get you a transposed (fields are now events) listing of the newest search job. 'sid' is the Search ID, and also the name of the folder in your dispatch directory.

0 Karma

sowings
Splunk Employee
Splunk Employee

Job results are stored in the dispatch directory on the search head: $SPLUNK_HOME/var/run/splunk/dispatch.

splunker12er
Motivator

Location : dispatch directory
Default storage period : 7 days (later it will be deleted)

0 Karma

sowings
Splunk Employee
Splunk Employee

The SID should match the name of the directory in there. I just ran a search, used the job inspector to find the SID: 1380118161.133, and sure enough, there's a directory by that name in the dispatch directory. Any others you see in there with a longer form, such as: scheduler__nobody__SplunkforPaloAltoNetworks__RMD548bd043d4f751080_at\_1380118200_27537 represent scheduled jobs.

0 Karma

jonathanfalconi
Explorer

Thanks - there are quite a few folders in dispatch dir, how can I work out where my particular job is? I do have the SID.

0 Karma
Get Updates on the Splunk Community!

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...