Splunk Search

Looking for a query to display a list of jobs stuck in queue (the past 7 days).

Ninja_splunk
Splunk Employee
Splunk Employee

I'm looking for a query to display a list of jobs stuck in queue (the past 7 days). Does anyone knows the query?

 

0 Karma

sainag_splunk
Splunk Employee
Splunk Employee

How about something like this to start with?

index=_internal sourcetype=splunkd log_level=WARN host=sh* component=DispatchManager "QUEUED" | stats count by host

 

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...

Index This | Divide 100 by half. What do you get?

November 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

❄️ Celebrate the season with our December lineup of Community Office Hours, Tech Talks, and Webinars! ...