sorting
in your search query is not permitted.
Workflows based on this trigger will search for new events every 5 minutes.
Parameters
Parameter | Description |
---|---|
Ad Hoc Search Level | The search level of the created search. For more information, refer to the Splunk Documentation. |
Execution Mode | Set to normal , in order to run an asynchronous search.Set to blocking , in order to return the sid when the job is complete. |
Search | The search query the created job will run. Important Note: The use of sorting in your search query is not permitted. |
Search Mode | Set to realtime to search live incoming data, or normal to run a one-time search over historical indexed data. |