Splunk® Enterprise

Monitor and Troubleshoot ingestion

Preview features described in this document are provided by Splunk to you "as is" without any warranties, maintenance and support, or service-level commitments. Splunk makes this preview feature available in its sole discretion and may discontinue it at any time. These documents are not yet publicly available and we ask that you keep such information confidential.
This documentation does not apply to the most recent version of Splunk® Enterprise. For documentation on the most recent version, go to the latest release.

How to stop scheduled searches

You can stop the Data monitoring app from running scheduled searches. To disable scheduled searches:

  1. Go to Settings > Searches, reports, and alerts to open the Searches, reports and alerts page.
  2. Select the following search criteria:
    • Type = "All"
    • App = "Data monitoring"
    • Owner = "Nobody"
  3. In the resulting list, locate "gdi_summarizer_ingestion_volume".
  4. Click Edit and select "Disable".

This will stop the scheduled searches and metrics will no longer be ingested into the gdi_summary_metrics index. Note that when you enable scheduled searches again, Data monitoring will not backfill the data for the time it was disabled. This means that there might be gaps in metrics reporting as you query the data on the dashboards.

To enable saved searches:

  1. Go to Settings > Searches, reports, and alerts to open the Searches, reports and alerts page.
  2. Select the following search criteria:
    • Type = "All"
    • App = "Data monitoring"
    • Owner = "Nobody"
  3. In the resulting list, locate "gdi_summarizer_ingestion_volume".
  4. Click Edit and select "Enable".
Last modified on 23 January, 2025
Install the Data monitoring preview app   Working with the Data monitoring dashboard

This documentation applies to the following versions of Splunk® Enterprise: DataMonitoringAppPreview


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters