Splunk Search

Can anyone provide a link or documentation with definitions of what each job status means?

DFresh4130
Path Finder

I've tried searching the documentation with no luck. Can anyone provide a link that gives a definition of what each job status means? I'm trying to understand the difference between done and finished jobs.

Tags (3)
1 Solution

ChrisG
Splunk Employee
Splunk Employee

Done means the search is completed. If you stop the search before it is completed, then when it finishes stopping, it is finalized.

There is some relevant information buried in the REST API Reference: http://docs.splunk.com/Documentation/Splunk/6.2.2/RESTREF/RESTsearch#search.2Fjobs.

We could do a better job with that in the documentation. Thanks for pointing it out, a writer will work on it!

View solution in original post

ChrisG
Splunk Employee
Splunk Employee

Done means the search is completed. If you stop the search before it is completed, then when it finishes stopping, it is finalized.

There is some relevant information buried in the REST API Reference: http://docs.splunk.com/Documentation/Splunk/6.2.2/RESTREF/RESTsearch#search.2Fjobs.

We could do a better job with that in the documentation. Thanks for pointing it out, a writer will work on it!

DFresh4130
Path Finder

Thanks for updating the docs. Can you elaborate on which statuses count toward a concurrent search limit?

0 Karma

somesoni2
SplunkTrust
SplunkTrust

Do you mean Done and Finalized? Below are valid job status values

QUEUED 
PARSING 
RUNNING 
PAUSED 
FINALIZING 
FAILED 
DONE 

DFresh4130
Path Finder

Correct. I often see my concurrent search limit of 10 searches being hit, but when I go to view jobs and sort by all running ones I only see 2 or 3 most of the time. Trying to understand what each of these means and see if that's what's causing me to hit the limit so often.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...