Splunk Search

Cont=f not sticking in Saved Searches

wbordeau
Explorer

After adding cont=f to my search I'm able to get the results I want but when I save the search and run it from the Saved Searches menu I find that the cont=f argument is absent from the search. Is there no way to save optional arguments in the search?

timechart
http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Timechart

Syntax
timechart [sep=] [partial=] [cont=] [limit=] [agg=] [ ]* ( [by ] ) | ( () by )

Optional arguments
cont
Syntax: cont=
Description: Specifies whether it's continuous or not.

0 Karma

wbordeau
Explorer

Btw, upgrading to Splunk 5.0.1 resolves this issue for me.

0 Karma

woodcock
Esteemed Legend

You should "Accept" your answer.

0 Karma

wbordeau
Explorer

When you execute the saved search, does the cont=f argument actually make it into the search or does it get truncated? Mine always truncates.

0 Karma

wbordeau
Explorer

Sorry, I meant to say it saves but when you go to run the saved search from the Searches & Reports menu the argument is lost. Effectively, it doesn't stick.

I'm using 4.3.4, build 136012.

0 Karma

sophy
Splunk Employee
Splunk Employee

Hi! I just tried to reproduce this and the option saves with the search. Can you give more details about your environment--What version of Splunk are you using? What is your search?

Thank you.

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...