Reporting

Why am I getting "Error in 'savedsearch' command: Unable to find saved search named..."?

ben_leung
Builder

splunkd.log

09-23-2014 19:17:05.101 +0000 ERROR SearchOperator:savedsplunk - Error in 'savedsearch' command: Unable to find saved search named 'ADSCV_SSP_REQUESTS'.

Running the command

| savedsearch ADSCV_SSP_REQUESTS

Gives me a UI error

Error in 'savedsearch' command: Unable to find saved search named 'ADSCV_SSP_REQUESTS'.

The saved search is scheduled under the same user trying to run the saved search command. The saved search has read access to all roles. The saved search is shared at the app level in the search app. What is causing this error?

Tags (2)
1 Solution

drrushi_splunk
Splunk Employee
Splunk Employee

Ben - can you ensure that the savedsearch in question is not Disabled? This would cause the above error.

View solution in original post

rupadantuluri1
New Member

i am facing error when running : hostname:port/services/search/jobs/export end point through postman

Input : search%3D%7C%20savedsearch%20MySavedSearch

Output :

<messages>
    <msg type="FATAL">Empty search.</msg>
</messages>

Same saved search is running in web successfully.

0 Karma

drrushi_splunk
Splunk Employee
Splunk Employee

Ben - can you ensure that the savedsearch in question is not Disabled? This would cause the above error.

ben_leung
Builder

Turns out that the search was disabled due to type. Had a default stanza in between a saved search, causing all of the underlying searches that was owned by the user to be disabled.

ben_leung
Builder

The saved search is shared at the app level, with read access to all roles. Other roles can run the | savedsearch command without getting the error.

ben_leung
Builder

I have ran the saved search command using an admin role user and was successful. I created a new account with the same role as the user that owns this search and has it scheduled. It also ran successful. Running it as the owner seems to be causing the error.

Please let me know how I can get this resolved.

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...