Hi Noura, The Splunk Free License is quite limited in functionality, but there might be a solution. Let's take a look at some of the limitations of the Splunk Free License that might be impacting your experience. Alerting (monitoring) is not available. Restrictions on search, such as user quotas, maximum per-search time ranges, and search filters are not supported. Report acceleration summaries are not available. Any alerts you defined no longer trigger. You no longer receive alerts from Splunk software. You can still schedule searches to run for dashboards and summary indexing purposes. As you can see, there are quite a few things that that might limit your ability to perform scheduled activities, but I suspect the last point is the one that you might be coming up against. The good news is that if your organisation is already a Splunk customer, Splunk offers a Developer License (exclusively for non-production use). There are a few restrictions, but scheduled searches and alerting should work just fine. You can read more about the Dev/Test license here You request a personalised Dev/Test license here Hope this helps! Regards, Devan www.4datasolutions.com
... View more