Knowledge Management

info_search_time vs search_now?

the_wolverine
Champion

What is the difference between the info_search_time vs search_now fields in my summary data?

Tags (2)
0 Karma

feorlen
Splunk Employee
Splunk Employee

info_search_time is the time it actually ran, search_now is when it was scheduled to run. You can sorta kinda see that by looking at info_search_time for addinfo (which is how some fields are generated) but there isn't much documented about the actual contents of the summary events. (I didn't go look at older versions of the docs to see if there was more before the si commands existed.)

Manually configure a search to populate a summary index

Get Updates on the Splunk Community!

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...