Reporting

Dashboard panels showing "In handler 'savedsearch': Error while dispatching search"

shaun_dyble
Explorer

Since upgrading to v6.1.4 some (not all) panels on a certain dashboard show an error "In handler 'savedsearch': Error while dispatching search".

I have found this solution, and changing the search to an inline search does get rid of the error. But Id rather find out the reason why its doing this now.

Has anyone else had panels using saved searches do this?

Thanks

Shaun

iststeam
Engager

In my case, this problem was solved by change the permission setting. I'm not sure does it can apply to your situation.

0 Karma

cafissimo
Communicator

Any news about this issue?

Thanks.

0 Karma

shaun_dyble
Explorer

I have confirmed with Splunk support that defect SPL-81881 has been raised for this and is currently an issue for all versions of 6.1

0 Karma

the_wolverine
Champion

According to known issues SPL-81881 is due to concurrency issues (searches being queued) or real-time search neither which was the case for us because the workaround was simply not to use Simple XML.

"In handler 'savedsearch': Error while dispatching search" may display due to searches being queued or could not run real time due to concurrency limits (SPL-81881)

arichman
Explorer

I am getting this same error when I try to save a report that features a macro in its query.

0 Karma

the_wolverine
Champion

This is occurring with our Simple XML dashboards. A bug is open with Splunk on it and we are waiting on Splunk DEV to figure it out. Try converting to Advanced XML as a workaround. It worked for us.

0 Karma

the_wolverine
Champion

Yes, happening here as well with 6.0.5. Would like to know the reason why.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...