Getting Data In

After we deleted a job it popped back up -- How can we delete it for good?

ddrillic
Ultra Champion

For some reason, we are not able to delete expired jobs as admin and as a power user who owns the jobs.

We choose, Job and then Delete Job. A pop message appears and disappears for a brief moment and the job remains with us.

Any ideas?

alt text

0 Karma

landen99
Motivator

Transfer Captain to clean-up captain's old and outdated search artifact records by going to Settings-Search Head Cluster under Distributed Environment and choosing the new captain to transfer to.

mayurr98
Super Champion
0 Karma

ddrillic
Ultra Champion

Not sure about the relation here ; -)

0 Karma

teunlaan
Contributor

What version are you running? Do you run a SH cluster?

We see the same issue in our SHclluster. It is releated with syncing betweens de SH's.
You're search is probably already deleted form te SH that was running it, but the Captain doesn't know that.
The "popup" is that it can't find the Job-ID.

We "Fix" it by selecting an other SH as master. Usually it will clean up after a while

mika703
Engager

That solved my issue, thanks. i also checked Splunk Known Issues and found the official Issue ID which is known since 2014

 

2014-10-02SPL-91638, SPL-107375For scheduled searches in a search head cluster, empty search jobs may appear in the job inspector for a cluster member.
0 Karma

ddrillic
Ultra Champion

Very interesting - have you filed any bug report on that, by any chance?

0 Karma

ddrillic
Ultra Champion

Let's see what Support would say...

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...