Other Usage

Is there a way to set the job TTL to a different value for a saved search?

bohrasaurabh
Communicator

Is there a way to set the job ttl to a different value for a saved search?

woodcock
Esteemed Legend

You can also use "| noop set_ttl = <NumberOfSecondsHere>"

0 Karma

guilmxm
SplunkTrust
SplunkTrust

bohrasaurabh gave you the answer, edit your search (in savedsearches.conf) As a line like:

dispatch.ttl = 3600

Note that the time is in seconds

bhawkins1
Communicator

Note that you can also specify the value as [0-9]+p, e.g. dispatch.ttl = 7p - this means "save 7 versions of the saved search".

You can then use old searches with, for example | loadjob savedsearch="x:y:z" artifact_offset=3

0 Karma

somesoni2
SplunkTrust
SplunkTrust
0 Karma

bohrasaurabh
Communicator

dispatch.ttl for savedsearch is different from jobs ttl. my understanding is jobs ttl defines how long the job will be in jobs activity.

0 Karma

risgupta_splunk
Splunk Employee
Splunk Employee

Yes, the TTL setting for the alert overrides the setting in savedsearches.conf, but you should set the TTL in both places. The TTL in alert_actions.conf only applies if an alert is triggered, otherwise the TTL in savedsearches.conf applies.

In both places, you can use the p notation or just the number of seconds to save.

There are also settings for TTL in limits.conf, but those only apply to ad hoc searches.

0 Karma

somesoni2
SplunkTrust
SplunkTrust

I guess you can update savedsearches.conf file for that saved search and set the dispatch.ttl to your configured value. Is that what you're looking for?

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...