Splunk Search

How to catch information from inspector job?

jip31
Motivator

Hi

I would like to catch the information in the example below:

This search has completed and has returned 1 000 résultat by scanning 2 610 582 événement in 220,758 seconds

These information comes from the job inspector.
How can I catch information and the response time?

Thanks a lot

Tags (1)
0 Karma
1 Solution

harsmarvania57
Ultra Champion

Hi,

You can access these details in _audit index. If you have access to _audit index then try to run search index=_audit search_id=* info=completed this will provide run time, event count, result count etc.

View solution in original post

0 Karma

harsmarvania57
Ultra Champion

Hi,

You can access these details in _audit index. If you have access to _audit index then try to run search index=_audit search_id=* info=completed this will provide run time, event count, result count etc.

0 Karma

jip31
Motivator

thanks a lot

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...