Splunk Search

MPLS_login_102_1 error message

alextsui
Path Finder

Hi. Some of the scheduled saved searches have stopped running. When click on these saved searches from Search App's "Searches & Reports" Navigation dropdown menu, the searches run fine. But when click on the "run" link of these saved searches from Manager > Searches and Reports, an error occurred on the web page like the screenshot display below:

alt text

If the screenshot picture does not display, the actual error message is listed below: "The following requested saved search is unknown""MPLS_login_102_1".As a result, Splunk is unable to redirect to a view."

Any suggestions to correct the problem?

Thanks.

Tags (1)
0 Karma

Genti
Splunk Employee
Splunk Employee

Check if the saved search is actually there. Look for and find all your savedsearches.conf files within your splunk/
Here are a couple of locations
./etc/apps/search/local/savedsearches.conf
./etc/system/default/savedsearches.conf
./etc/users/admin/search/local/savedsearches.conf

and then check your splunk/var/run/splunk/dispatch directory and see if a savedsearch with the above name is scheduled to run. If there is no saved search but still the search is scheduled, delete the scheduled search (rmdir) and you should not be seeing those errors.
If the saved search exists but you still see that error, send your diag to support and they should be able to troubleshoot this issue..

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

It is also possible that the searches are marked "not visible" or that they are private to only one specific user, or not readable to a user in your role.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...