Splunk Search

Create a failed search job

inventsekar
SplunkTrust
SplunkTrust

Hi, for a testing purpose, i would like to create a failed search job.. i did search for this, but no luck.. any suggestions please

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
Labels (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

Write a scheduled saved search with an illegal eval statement or a macro that doesn't exist? That will then run and create a job failure - is that what you wanted?

 

inventsekar
SplunkTrust
SplunkTrust

Thanks @bowesmana .. that works fine. 

@richgalloway .. i would like to run a search which will fail. 

 

Let me give more info.. in our clustered environment, at random times, user's search queries status in JOBS say "failed", but still continuous to run for very long time.. even for weeks. 

is there any way to clear these "failed jobs" please. 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

@bowesmana gave a few good suggestions to create a job that will fail.

Search _internal to find failed jobs.

Kill a failed job at Activities->Jobs and then click the Stop icon for the appropriate job.

---
If this reply helps you, Karma would be appreciated.
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Suggestions for what, creating a failed job or searching for one?  What do you consider "failed"?

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...