Splunk Search

Create a failed search job

inventsekar
SplunkTrust
SplunkTrust

Hi, for a testing purpose, i would like to create a failed search job.. i did search for this, but no luck.. any suggestions please

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
Labels (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

Write a scheduled saved search with an illegal eval statement or a macro that doesn't exist? That will then run and create a job failure - is that what you wanted?

 

inventsekar
SplunkTrust
SplunkTrust

Thanks @bowesmana .. that works fine. 

@richgalloway .. i would like to run a search which will fail. 

 

Let me give more info.. in our clustered environment, at random times, user's search queries status in JOBS say "failed", but still continuous to run for very long time.. even for weeks. 

is there any way to clear these "failed jobs" please. 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

@bowesmana gave a few good suggestions to create a job that will fail.

Search _internal to find failed jobs.

Kill a failed job at Activities->Jobs and then click the Stop icon for the appropriate job.

---
If this reply helps you, Karma would be appreciated.
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Suggestions for what, creating a failed job or searching for one?  What do you consider "failed"?

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.0.2 Availability: On cloud and On-premise!

A few months ago, we released Splunk Enterprise Security 8.0 for our cloud customers. Today, we are excited to ...

Logs to Metrics

Logs and Metrics Logs are generally unstructured text or structured events emitted by applications and written ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...