Hello all.. i have a scheduled job which will run for every 1 hr and store results in summary index and send an email with search results. so far so good, but problem i am facing is, search results are expiring after 24 hrs which is causing data limit on my account. after some investigation i found that, if there is an email alert, splunk by default will store results for 24 hrs. so, i removed email alert and search results are expiring after 1 hr (which really solved my problem).
using above approach, since there is no email after 1 hr job runs, i don't know whether hrly jobs are running fine or not. so, i want to get an email alert (no link to search results) with expiry as 1 hr. could someone help me on how to solve this problem.
Note: i dont have permissions to change values in alert_actions.conf, savedsearches.conf .. etc
thanks in advance
Read the options for dispatch.ttl
in this document:
https://docs.splunk.com/Documentation/Splunk/latest/Admin/Savedsearchesconf
https://docs.splunk.com/Documentation/SplunkCloud/7.0.3/Alert/Updatealerts
See the section on "Configure triggered alert expiration"
i don't see the option which was mentioned in splunk documentation because of this "These steps apply only to alerts with the "Add to Triggered Alerts" action enabled." looks like i don't have permission to set this setting.