Splunk Search

Why I have very old time in my job list?

jujis008
Explorer

Dear All Splunkers,
I've a very problem in my job list which is I got the oldest query, but actually there is not conditions in search body.
alt text

so my queries was hanged, there was nothing except I build a dashboard for some queries.

does any one have the same issue?

thank you all

Tags (1)
1 Solution

snoobzilla
Builder

I suspect these are scheduled jobs that have not started yet (and should have) so if your instance is running behind on scheduled jobs these start to stack up... which of course is exactly when you are most likely to be looking at activity, when things are slow. Suspicion is based on feedback from case we are working through with Splunk.

Take a look at your skipped jobs ratio at the same time you are seeing these in DMC app/splunk_management_console/scheduler_activity_deployment

See also https://answers.splunk.com/answers/321611/why-are-jobs-showing-as-dispatched-at-123169-and-k.html

View solution in original post

snoobzilla
Builder

I suspect these are scheduled jobs that have not started yet (and should have) so if your instance is running behind on scheduled jobs these start to stack up... which of course is exactly when you are most likely to be looking at activity, when things are slow. Suspicion is based on feedback from case we are working through with Splunk.

Take a look at your skipped jobs ratio at the same time you are seeing these in DMC app/splunk_management_console/scheduler_activity_deployment

See also https://answers.splunk.com/answers/321611/why-are-jobs-showing-as-dispatched-at-123169-and-k.html

View solution in original post

jujis008
Explorer

Exactly, I noticed this is because there are some queries not start yet and showing the start time as 0 this morning. thank you very much!

0 Karma

jujis008
Explorer

is there any possible that's a bug in Splunk? anyone got the same issue?

0 Karma

sheamus69
Communicator

Have you checked your clock settings on your Splunk boxes?

Also, that happens if you inspect those jobs?

0 Karma

jujis008
Explorer

yes, clock setting is good, even I want to set time as 1/1/70 there will pop up errors.
no, not to inspect jobs. but if i click inspect job, there will a 500 internal error page.
error details as following:
500 Internal Server Error

Return to Splunk home page

View more information about your request (request ID = 578c7309667f4ac88bcc50) in Search

This page was linked to from https://cloudsearch-dc13.cld.XXXXXand.com/en-US/app/search/job_management.

You are logged into search-dc13.cld.XXXXXand.com as i324291, which is connected to splunkd @255606 at https://127.0.0.1:8089 on Mon Jul 18 06:11:21 2016.

however, i find some clues on the url.
app/search/test_clone?form.fieldtimeperf.earliest=-4h%40m&
form.fieldtimeperf.latest=now&
form.fieldtimeperf1.earliest=-24h%40h&
form.fieldtimeperf1.latest=now&
form.fieldtimeperf2.earliest=-24h%40h&
form.fieldtimeperf2.latest=now&
form.fieldtimeusercpu.earliest=-4h%40m&
form.fieldtimeusercpu.latest=now&
form.fieldtimesyscpu.earliest=-4h%40m&
form.fieldtimesyscpu.latest=now&
form.fieldtimettcpu.earliest=-4h%40m&
form.fieldtimettcpu.latest=now&
earliest=0&
latest=

the last parameters will be added automatically, even if you removed it manually, but no sure if cause by the parameter

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!