Security

Error in 'SearchParser': Missing a search command before ' '.

alenseb
Communicator

Hi,

I am trying to access one of my saved Searches, but this error is shown all of a sudden.
My syntax is correct as the same code was working sometime back.
Is this a product bug?

Please help.

Thanks!!

0 Karma

ryonts
Explorer

I discovered today that after modifying a saved search to format it for better readability, this error showed up. The problem was that in formatting it, I added some CRLF characters. Afterwards, the error showed up. For some reason, CRLF are NOT ignored, but affect the search string. Hopefully this can help your situation. (I HATE unformatted search strings, too difficult to read when all jumbled up!)

0 Karma

ryonts
Explorer

I discovered today that after modifying a saved search to format it for better readability, this error showed up. The problem was that in formatting it, I added some CRLF characters. Afterwards, the error showed up. For some reason, CRLF are NOT ignored, but affect the search string. Hopefully this can help your situation. (I HATE unformatted search strings, too difficult to read when all jumbled up!)

MarioM
Motivator

to get help you need to give more infos:
-post the complete search
-splunk version
-permissions of the searches/report/dashboards/apps...

0 Karma

alenseb
Communicator

Just read somewhere for these of errors, you have to re-install.
Any idea on why?

0 Karma

alenseb
Communicator

i haven't changed anything.

0 Karma

MuS
SplunkTrust
SplunkTrust

so what did change since it last was working?

0 Karma

alenseb
Communicator

The search works just fine, but when i search as a | savedsearch i get the error.

Also the same SavedSearch command was working fine sometime back.

0 Karma

lguinn2
Legend

We need to see the actual search text. Go to the Manager and edit the saved search. Copy the search into a comment.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...