Splunk Search

where are job manager search results stored

jonathanfalconi
Explorer

Hi - Where are the job manager search results stored on the disk if I want to find it via CLI?

Tags (2)
0 Karma

Jason
Motivator

If you need to know where a particular search result is, use a REST search.

| rest splunk_server=local count=0 /services/search/jobs | rename title as searchString | rename label as searchName | table searchName searchString sid | search searchName="...etc"

This will get you a transposed (fields are now events) listing of the newest search job. 'sid' is the Search ID, and also the name of the folder in your dispatch directory.

0 Karma

sowings
Splunk Employee
Splunk Employee

Job results are stored in the dispatch directory on the search head: $SPLUNK_HOME/var/run/splunk/dispatch.

splunker12er
Motivator

Location : dispatch directory
Default storage period : 7 days (later it will be deleted)

0 Karma

sowings
Splunk Employee
Splunk Employee

The SID should match the name of the directory in there. I just ran a search, used the job inspector to find the SID: 1380118161.133, and sure enough, there's a directory by that name in the dispatch directory. Any others you see in there with a longer form, such as: scheduler__nobody__SplunkforPaloAltoNetworks__RMD548bd043d4f751080_at\_1380118200_27537 represent scheduled jobs.

0 Karma

jonathanfalconi
Explorer

Thanks - there are quite a few folders in dispatch dir, how can I work out where my particular job is? I do have the SID.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...