All Apps and Add-ons

Search is "scheduled", but shows no schedule in manager and didn't run

sowings
Splunk Employee
Splunk Employee

I've recently installed the Fire Brigade app on a new single-instance Splunk, running version 5. The saved searches didn't fire overnight, and I'm wondering why. I went into the Manager > Searches and Reports, and saw that the "scheduled time" field for the searches were all blank. Thinking that this must have been an installation snafu, I clicked on the search to enable a schedule. What I found was that it was already showing as scheduled, with the correct time. Despite this, it hadn't run.

Any hints?

alt text

1 Solution

sowings
Splunk Employee
Splunk Employee

The issue was observed in 5.0. Since upgrading the system to 5.0.4, the app's searches show as scheduled, and everything seems OK.

View solution in original post

sowings
Splunk Employee
Splunk Employee

The issue was observed in 5.0. Since upgrading the system to 5.0.4, the app's searches show as scheduled, and everything seems OK.

hexx
Splunk Employee
Splunk Employee

You could at least upvote my comments 🙂

0 Karma

sowings
Splunk Employee
Splunk Employee

Upgrading to 5.0.4 has ... vanished the problem.

0 Karma

hexx
Splunk Employee
Splunk Employee

If this is occurring in the latest version (5.0.4), please file a support case and/or a bug.

sowings
Splunk Employee
Splunk Employee

Schedule is correct, search is not disabled.

It looks like the REST API is disagreeing with the manager.

0 Karma

hexx
Splunk Employee
Splunk Employee

I would look at the scheduling-specific properties of the saved search object in the REST API.

Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...