Splunk Search

Is this a scheduled real-time search?

a212830
Champion

Hi,

Are processes that contain "rt_scheduler" real-time scheduled searches?

Example:

splunk 15005 75443 0 10:20 ? 00:00:00 [splunkd pid=75442] search --id=remote_azone567_rt_scheduler_Z527062gns_BillPay_at_1459002000_14090 --maxbuckets=0 --ttl=60 --maxout=0 --maxtime=0 --lookups=1 --streaming --outCsv=true --user=username_removed_for_answers_post --pro --roles=dbx_user:power:user

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Should be. To be certain, search index=_audit for that search ID and look for the oldest event, it should contain lots of info about the search.

0 Karma

sloshburch
Splunk Employee
Splunk Employee

I wonder if you can also check the search activity or jobs list to see the corresponding search and view what actually was run.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Yeah, but that's only visible for as long as the job artefacts exist.

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...