<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Mysterious realtime search generating 100s of jobs in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Mysterious-realtime-search-generating-100s-of-jobs/m-p/84569#M21554</link>
    <description>&lt;P&gt;We recently upgraded to Splunk 6 and on multiple occasions a real-time search seems to magically appear and causes all other searches/dashboards to halt because the limit for searches has been reached. When I check all running jobs I see 100s of real-time searches "&lt;CODE&gt;|&lt;/CODE&gt;" (a single pipe) with no start-time or end-time by the user Admin. Initially, I thought this may be related to work on a real-time dashboard and post-process searches, but the dashboard is in a different app than where these mysterious searches are reportedly running.&lt;/P&gt;

&lt;P&gt;To resolve the issue, I restart Splunk and delete the searches out of the dispatch directory. Simply trying to stop/delete them from the job management app will not work. &lt;/P&gt;

&lt;P&gt;Is there any way to determine what is causing this? Could this be a bug in version 6?&lt;/P&gt;</description>
    <pubDate>Sun, 06 Oct 2013 15:30:23 GMT</pubDate>
    <dc:creator>sc0tt</dc:creator>
    <dc:date>2013-10-06T15:30:23Z</dc:date>
    <item>
      <title>Mysterious realtime search generating 100s of jobs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Mysterious-realtime-search-generating-100s-of-jobs/m-p/84569#M21554</link>
      <description>&lt;P&gt;We recently upgraded to Splunk 6 and on multiple occasions a real-time search seems to magically appear and causes all other searches/dashboards to halt because the limit for searches has been reached. When I check all running jobs I see 100s of real-time searches "&lt;CODE&gt;|&lt;/CODE&gt;" (a single pipe) with no start-time or end-time by the user Admin. Initially, I thought this may be related to work on a real-time dashboard and post-process searches, but the dashboard is in a different app than where these mysterious searches are reportedly running.&lt;/P&gt;

&lt;P&gt;To resolve the issue, I restart Splunk and delete the searches out of the dispatch directory. Simply trying to stop/delete them from the job management app will not work. &lt;/P&gt;

&lt;P&gt;Is there any way to determine what is causing this? Could this be a bug in version 6?&lt;/P&gt;</description>
      <pubDate>Sun, 06 Oct 2013 15:30:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Mysterious-realtime-search-generating-100s-of-jobs/m-p/84569#M21554</guid>
      <dc:creator>sc0tt</dc:creator>
      <dc:date>2013-10-06T15:30:23Z</dc:date>
    </item>
    <item>
      <title>Re: Mysterious realtime search generating 100s of jobs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Mysterious-realtime-search-generating-100s-of-jobs/m-p/84570#M21555</link>
      <description>&lt;P&gt;Just curious on the job management app - whats it?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Dec 2013 16:01:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Mysterious-realtime-search-generating-100s-of-jobs/m-p/84570#M21555</guid>
      <dc:creator>splunkears</dc:creator>
      <dc:date>2013-12-20T16:01:57Z</dc:date>
    </item>
    <item>
      <title>Re: Mysterious realtime search generating 100s of jobs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Mysterious-realtime-search-generating-100s-of-jobs/m-p/84571#M21556</link>
      <description>&lt;P&gt;I was referring to the job manager; not really a separate app.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2014 14:44:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Mysterious-realtime-search-generating-100s-of-jobs/m-p/84571#M21556</guid>
      <dc:creator>sc0tt</dc:creator>
      <dc:date>2014-01-06T14:44:27Z</dc:date>
    </item>
    <item>
      <title>Re: Mysterious realtime search generating 100s of jobs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Mysterious-realtime-search-generating-100s-of-jobs/m-p/84572#M21557</link>
      <description>&lt;P&gt;I would suspect that this could be one of a couple of things (that I can think of).&lt;BR /&gt;
How tight is your control of searches on the box? Is it possible that users have created lots of subsearches or real time searches and used the map command? I can't recall of the top of my head how this would appear in the job manager but it might fit the pattern.&lt;/P&gt;

&lt;P&gt;Another option is that you have a couple of dashboards which have some oddly created searches that are impacting in v6 but weren't in v5? Can you do a search through your audit/internal logs to see where these searches are firing from.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2014 19:07:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Mysterious-realtime-search-generating-100s-of-jobs/m-p/84572#M21557</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2014-01-06T19:07:28Z</dc:date>
    </item>
    <item>
      <title>Re: Mysterious realtime search generating 100s of jobs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Mysterious-realtime-search-generating-100s-of-jobs/m-p/84573#M21558</link>
      <description>&lt;P&gt;Good questions and suggestions. I'll dig into those deeper to see if I can isolate the issue. I'll follow up.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2014 16:37:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Mysterious-realtime-search-generating-100s-of-jobs/m-p/84573#M21558</guid>
      <dc:creator>sc0tt</dc:creator>
      <dc:date>2014-01-14T16:37:58Z</dc:date>
    </item>
  </channel>
</rss>

