Reporting

In the scheduler.log, what does status=continued mean?

sowings
Splunk Employee
Splunk Employee

I see a number of events in my scheduler.log that have the string "status=continued" in them. Further, these entries lack the run_time (and other fields) that would seem to indicate successful saved search completion. What do these log events represent?

Tags (1)

wsnyder2
Path Finder

Can we assume that status=skipped is a "not" so good thing?

0 Karma

somesoni2
Revered Legend

In my understanding, when a search is configured for continuous scheduling (realtime_schedule = 0) and no of concurrent searches exceeds the limit, Splunk will add an entry with status=continued as the search execution is queued up. It should log another entry with status=success or status=fail when search is executed after it's turn comes up.

0 Karma

jluste
Path Finder

I'd also like to know what continued means officially and if it is the case of a deferred search, how long goes by before that search gets set to status=skipped?

0 Karma

sowings
Splunk Employee
Splunk Employee

My observation is that it's when a prior instance of the search is running, but the time has come for it to run again.

If anyone has an updated answer, I'd appreciate it.

mloven_splunk
Splunk Employee
Splunk Employee

bumping this. I'd like to know as well.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...