1.

Explain what is Dispatch Directory.

Answer»

A directory is INCLUDED in the Dispatch Directory for each search that is running or has been completed. 

The Dispatch Directory is configured as follows: 

$SPLUNK_HOME/var/run/splunk/dispatch

Take the example of a directory named 14333208943.348. This directory includes a CSV file of all search results, a search.log CONTAINING details/information about the search execution, as WELL as other pertinent information. You can delete this directory WITHIN 10 minutes after the search is completed using the default configuration. Search results are DELETED after seven days if you have saved them. 



Discussion

No Comment Found