Splunk Search

Question regarding Search Jobs

misteryuku
Communicator

What is meant by creating new search job that runs "search error" ?

Tags (1)
0 Karma

Masa
Splunk Employee
Splunk Employee

What is "search error" ?

0 Karma

misteryuku
Communicator

I'm very new to Splunk and i just want to know.

0 Karma

Masa
Splunk Employee
Splunk Employee

When you run a search, Splunk create a search job. From a process point of view, there is a splunkd child process and its helper process for each search. When a search job is also related to a directory which contains search logs, reults, and meta data. This directory is also called a dispatch directory. The search job's id which is called sid is the search job's dipatch directory.

You can find dispatch jobs under $SPLUNK_HOME/var/run/splunk/dispatch directory. Except for troubleshooting by Support, usueally users never need to go visit there to retrive data manually.

Masa
Splunk Employee
Splunk Employee

Could you describe a litte bit more detail? Step by step what you tried?

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...