You can use the job.touch()
method to keep the job alive for the given ttl (time to live) or modify the ttl by using job.setttl(<ttl in seconds>)
.
"Touching" the job every few thousand events might be a good idea. Additionally, using job.cancel()
when you've finished processing the results can be used to remove the job.
job.setttl(86400);
processEvents(job);
job.cancel();
You can see more info here: http://splunk-base.splunk.com/answers/50722/the-search-results-disappear-how-to-keep-them-longer-pyt...