Quantcast
Viewing all articles
Browse latest Browse all 47296

How to troubleshoot why previously working scheduled reports and new scheduled searches are not running?

Previously working scheduled reports are not working AND newly created reports are not working. Creating a new test search works: index=test1 | timechart count by status The timechart is created, but putting this search into a report doesn't work: index=test1 | timechart count by status | collect index=test2 ... no scheduled search is run and no data is collected into index=test2 I've check my user/role permissions, and they seem fine .. admin access I've checked the licensing, no limits reached No recent search head changes I've adjusted report/schedule times 5, 15, 1hr (cron & basic) I've enabled/disabled summary indexing within reports I've checked the search app for permissions.. admin read/write, global, sharing-config all_apps I've deleted the original report and recreated it Splunk 6.4 - enterprise Another admin here was updating app permissions, refining global sets a few days before, but he assures this shouldn't be the issue. If this was the problem, the only app I can see that may be the issue would be the Search app .. which i have admin access in. **Is there a global app permission that needs to be enabled/adjusted? Any other advice on what to check or do?** Thank You

Viewing all articles
Browse latest Browse all 47296

Trending Articles