Reporting

Scheduled Saved Search Retention

hjwang
Contributor

Hi~there,

As I crawl related article, I know this can be done by adding dispatch.ttl=(int)p in savedsearches.conf and overwritten in alert_action.conf where p represents scheduled search's period, right? now i have one schedule saved search run on the 1st of each month. but i found its expired time just one day more after run time on job status. Is this normal or anything else? futhermore, if I do save job on job UI , does it mean eternal retention? next time when run this search again, will this be overwritten?

Thanks

0 Karma

risgupta_splunk
Splunk Employee
Splunk Employee

Yes, the TTL setting for the alert overrides the setting in savedsearches.conf, but you should set the TTL in both places. The TTL in alert_actions.conf only applies if an alert is triggered, otherwise the TTL in savedsearches.conf applies.

In both places, you can use the p notation or just the number of seconds to save.

There are also settings for TTL in limits.conf, but those only apply to ad hoc searches.

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...