Reporting

Setting for cleaning scheduled saved search artifacts after its fulfilling

iKate
Builder

Hi!
What setting in advanced edit list of a scheduled saved search stands for cleaning search artifacts after its fulfilling?

I have a scheduled saved search that runs about 30 minutes and generates a file of lets say 1Gb, after this I cannot search anything with an error message that I've exhausted space limit for my user. And I need to clean my jobs then.

Thanks!

0 Karma

woodcock
Esteemed Legend

In the advanced setting area of your scheduled saved search, you can configure the TTL for the artifacts. For big ones like this, set it to very low (like 10 seconds).

0 Karma

SamHTexas
Builder

Please show me where (which Splunk server) this advanced setting area is located & how to change the TTL. Thank u

Tags (1)
0 Karma

arjunpkishore5
Motivator

Set an expiry for the saved search as mentioned by @DalJeanis in this post - https://answers.splunk.com/answers/666162/how-to-set-expiry-time-for-saved-scheduled-search-1.html

Please mark as answer if this solves your problem.

0 Karma

iKate
Builder

Thanks, it was exactly what I needed: alert.expires

0 Karma

iKate
Builder

Unfortunately it's not. Though I applied this setting artifacts still exist long time after report was fulfilled.
Maybe it's because I have saved reports and this setting is only for alerts?
I see lots of settings related to dispatch, but I need not to delete search after it has been running for 2 minutes, but to clean it in two minutes after it completes and its completion can take 30 minutes or so.

0 Karma

arjunpkishore5
Motivator

Trying to understand the use-case. Do you want to kill the search if it's running for longer than 2 mins ?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

There is no per-search setting controlling how long search artifacts remain after a search. IIRC, the default is twice the interval of the search.
Ask your admin to increase the search quota for your account/role.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...