Splunk Search

Searches and reports Cache

pero1234
Path Finder

How to clean Searches and reports cache?

I just rename stanza from [Report TEST] to [Report All Users] in my savedsearches.conf but that report on email is still under name 'Report TEST'!!!

After research all my savedsearches.conf files I saw that I have another [Report TEST] and my new one [Report All Users] with the same parameters and search!

/opt/splunk/etc/apps/search/local/savedsearches.conf

[Report TEST]
alert.suppress = 0
alert.track = 1
counttype = number of events
cron_schedule = */10 * * * *
dispatch.earliest_time = -10m@m
dispatch.latest_time = now
enableSched = 1
quantity = 0
relation = greater than
search = index=myindex sourcetype=mysourcetype test1

/opt/splunk/etc/apps/search/local/savedsearches.conf

[Report All Users]
alert.suppress = 0
alert.track = 1
counttype = number of events
cron_schedule = */10 * * * *
dispatch.earliest_time = -10m@m
dispatch.latest_time = now
enableSched = 1
quantity = 0
relation = greater than
search = index=myindex sourcetype=mysourcetype test1

'Report TEST' works but 'Report All Users' don't!!!! Why?????

Tags (3)
0 Karma

hjwang
Contributor

Restart your splunk to reload new configure file

0 Karma

pero1234
Path Finder

Restart did not help!

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...