Splunk Search

Create a failed search job

inventsekar
SplunkTrust
SplunkTrust

Hi, for a testing purpose, i would like to create a failed search job.. i did search for this, but no luck.. any suggestions please

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
Labels (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

Write a scheduled saved search with an illegal eval statement or a macro that doesn't exist? That will then run and create a job failure - is that what you wanted?

 

inventsekar
SplunkTrust
SplunkTrust

Thanks @bowesmana .. that works fine. 

@richgalloway .. i would like to run a search which will fail. 

 

Let me give more info.. in our clustered environment, at random times, user's search queries status in JOBS say "failed", but still continuous to run for very long time.. even for weeks. 

is there any way to clear these "failed jobs" please. 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

@bowesmana gave a few good suggestions to create a job that will fail.

Search _internal to find failed jobs.

Kill a failed job at Activities->Jobs and then click the Stop icon for the appropriate job.

---
If this reply helps you, Karma would be appreciated.
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Suggestions for what, creating a failed job or searching for one?  What do you consider "failed"?

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...