Monitoring Splunk

Search.log records related to past search

lukasmecir
Path Finder

Hi,

I have question about search.log. I know I can find log records related to particular search in search.log using Job inspector (clicking on link to search.log in bottom of Job inspector). But my question is: is there any way how to get records related to particular search in past? Example: I made some search yesterday and today I would like to get all log records related to this search from search.log file. Is there any way how to do it? Thanks in advance for any info or hint.

Best regards

Lukas

Labels (1)
Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

By default, ad-hoc search results expire after 10 minutes so there's no way to get the log for yesterday's searches, unless you used the Share button to extend the expiration time of the search.

---
If this reply helps you, Karma would be appreciated.
0 Karma

lukasmecir
Path Finder

Thanks for info, honestly I was afraid about it, but it is good to get confirmation from someone well experienced. Just for clarification - it means, that all records related to particular search are deleted from search.log file 10 minutes after search was performed (with default setting)?

0 Karma
Get Updates on the Splunk Community!

Get ready to show some Splunk Certification swagger at .conf24!

Dive into the deep end of data by earning a Splunk Certification at .conf24. We're enticing you again this ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Now On-Demand Join us to learn more about how you can leverage Service Level Objectives (SLOs) and the new ...

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...