I have some searches that I've scheduled to populate a summary index, but I want to get historical info from them as well so I attempted to backfill the index using the fill_summary_index.py script.
However, when I tried this, I get the following error output:
[root@ bin]# ./splunk cmd python fill_summary_index.py
Please enter the app that contains the search(es): search
Please enter the name of saved search #1 (empty value to stop entering): zzz - DO NOT RUN - DataTable Top Ten Summary Index Search
Please enter the name of saved search #2 (empty value to stop entering):
Please enter your splunk username: andrewn
Please enter your splunk password:
Please enter the earliest time (UTC or relative): -6w@w
Please enter the latest time (UTC or relative): -w
*** For saved search 'zzz - DO NOT RUN - DataTable Top Ten Summary Index Search' ***
Failed to get list of scheduled times for saved search 'zzz - DO NOT RUN - DataTable Top Ten Summary Index Search' (app = 'search', error = '[HTTP 404] https://127.0.0.1:8089/servicesNS/nobody/search/saved/searches/zzz%20-%20DO%20NOT%20RUN%20-%20DataTa...; None'
No searches to run
I've confirmed that the owner of the search is nobody
, and I've tried running it with -dedup
set and unset, and nothing seems to be working. Why am I getting this error?
Other info:
splunk.ResourceNotFound
Exception - does this help shed some light?I found that the reason I was getting this issue was one of data sync (I think) - I went into my savedsearches.conf
and couldn't find the report, even though it was listed (with full search info, mind) in the Manager UI. Deleting and re-inserting the search via the manager resolved the issue and my backfill worked fine…
I encounter this when I forget to "share" my summary search to the search app. I don't have to specifically assign privs to any role but the search app needs access. 2 clicks in UI will fix it.
I found that the reason I was getting this issue was one of data sync (I think) - I went into my savedsearches.conf
and couldn't find the report, even though it was listed (with full search info, mind) in the Manager UI. Deleting and re-inserting the search via the manager resolved the issue and my backfill worked fine…
that was the main file I was looking in, yes…
So your saved/scheduled search was not found in any savedsearches.conf, even the one in $SPLUNK_HOME/etc/users/yourusername?
Hi Andrew, I have seen this error when the -owner flag is not specified. What happens when you add the -owner flag?
The UI manager claimed that it was both saved and scheduled - I've since discovered the problem, see my answer for info. Thanks for your help, though!
Have you scheduled the search or is it simply saved?
Hi hulahoop,
I've tried specifying nobody
(what the manager reports as the owner), and I still get the same result 😞