Splunk Search

Create a failed search job

inventsekar
SplunkTrust
SplunkTrust

Hi, for a testing purpose, i would like to create a failed search job.. i did search for this, but no luck.. any suggestions please

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
Labels (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

Write a scheduled saved search with an illegal eval statement or a macro that doesn't exist? That will then run and create a job failure - is that what you wanted?

 

inventsekar
SplunkTrust
SplunkTrust

Thanks @bowesmana .. that works fine. 

@richgalloway .. i would like to run a search which will fail. 

 

Let me give more info.. in our clustered environment, at random times, user's search queries status in JOBS say "failed", but still continuous to run for very long time.. even for weeks. 

is there any way to clear these "failed jobs" please. 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

@bowesmana gave a few good suggestions to create a job that will fail.

Search _internal to find failed jobs.

Kill a failed job at Activities->Jobs and then click the Stop icon for the appropriate job.

---
If this reply helps you, Karma would be appreciated.
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Suggestions for what, creating a failed job or searching for one?  What do you consider "failed"?

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 3)

Welcome back to Splunk Classroom Chronicles, our ongoing blog series that pulls back the curtain on Splunk ...

Operationalizing TDIR: Building a More Resilient, Scalable SOC

Optimizing SOC workflows with a unified, risk-based approach to Threat Detection, Investigation, and Response ...

Almost Too Eventful Assurance: Part 1

Modern IT and Network teams still struggle with too many alerts and isolating issues before they are notified. ...