Alerting

how do i get rid of recurring "Error in 'SearchOperator:loadjob':..."?

sophy
Splunk Employee
Splunk Employee

This was a question from IRC:

How do I get rid of recurring "Error in 'SearchOperator:loadjob': Cannot find artifacts within the search time range for savedsearch_ident 'xxxx'"?

sophy
Splunk Employee
Splunk Employee

from captain albania:

This occurs the first time a scheduled search that has an alert condition of the the form "rises/drops by" is execute. The reason for this error is that "rises/drops by" requires the artifacts of the previous scheduled time to be present to perform the comparison. If they're not this error is thrown.

Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...