Dashboards & Visualizations

How to refresh saved search in Splunk 6.5.1?

nmouli
Explorer

Hi -

I have saved search scheduled for every 10min but the latest results are not getting reflected in dashboard.

Tried using the refresh.auto.interval option but it was deprecated in Splunk 6.5.1 and since all the panels are using post processing search, can't see the refresh delay options in edit panels.

please suggest. Thanks in advance!

0 Karma
1 Solution

nmouli
Explorer

I have tried with refresh tag under search tag and it works.

< search id="base_search" ref="saved_search" >
< refresh> 60s < /refresh>
< /search>

View solution in original post

0 Karma

nmouli
Explorer

I have tried with refresh tag under search tag and it works.

< search id="base_search" ref="saved_search" >
< refresh> 60s < /refresh>
< /search>

0 Karma

aaraneta_splunk
Splunk Employee
Splunk Employee

@nmouli - Is this the working solution to your question? If yes, please don't forget to click "Accept" to resolve this question.

Also, for future reference, when posting a sample code wrapped in brackets <search> or sample search with special characters such as an asterisk *, you should wrap it in a Code Sample for proper formatting. Simply click on the Code Sample icon to the right of the Blockquote icon in the formatting toolbar. Thanks.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...