Splunk Search

Cont=f not sticking in Saved Searches

wbordeau
Explorer

After adding cont=f to my search I'm able to get the results I want but when I save the search and run it from the Saved Searches menu I find that the cont=f argument is absent from the search. Is there no way to save optional arguments in the search?

timechart
http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Timechart

Syntax
timechart [sep=] [partial=] [cont=] [limit=] [agg=] [ ]* ( [by ] ) | ( () by )

Optional arguments
cont
Syntax: cont=
Description: Specifies whether it's continuous or not.

0 Karma

wbordeau
Explorer

Btw, upgrading to Splunk 5.0.1 resolves this issue for me.

0 Karma

woodcock
Esteemed Legend

You should "Accept" your answer.

0 Karma

wbordeau
Explorer

When you execute the saved search, does the cont=f argument actually make it into the search or does it get truncated? Mine always truncates.

0 Karma

wbordeau
Explorer

Sorry, I meant to say it saves but when you go to run the saved search from the Searches & Reports menu the argument is lost. Effectively, it doesn't stick.

I'm using 4.3.4, build 136012.

0 Karma

sophy
Splunk Employee
Splunk Employee

Hi! I just tried to reproduce this and the option saves with the search. Can you give more details about your environment--What version of Splunk are you using? What is your search?

Thank you.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...