Reporting

Why am I getting "Error in 'savedsearch' command: Unable to find saved search named..."?

ben_leung
Builder

splunkd.log

09-23-2014 19:17:05.101 +0000 ERROR SearchOperator:savedsplunk - Error in 'savedsearch' command: Unable to find saved search named 'ADSCV_SSP_REQUESTS'.

Running the command

| savedsearch ADSCV_SSP_REQUESTS

Gives me a UI error

Error in 'savedsearch' command: Unable to find saved search named 'ADSCV_SSP_REQUESTS'.

The saved search is scheduled under the same user trying to run the saved search command. The saved search has read access to all roles. The saved search is shared at the app level in the search app. What is causing this error?

Tags (2)
1 Solution

drrushi_splunk
Splunk Employee
Splunk Employee

Ben - can you ensure that the savedsearch in question is not Disabled? This would cause the above error.

View solution in original post

rupadantuluri1
New Member

i am facing error when running : hostname:port/services/search/jobs/export end point through postman

Input : search%3D%7C%20savedsearch%20MySavedSearch

Output :

<messages>
    <msg type="FATAL">Empty search.</msg>
</messages>

Same saved search is running in web successfully.

0 Karma

drrushi_splunk
Splunk Employee
Splunk Employee

Ben - can you ensure that the savedsearch in question is not Disabled? This would cause the above error.

ben_leung
Builder

Turns out that the search was disabled due to type. Had a default stanza in between a saved search, causing all of the underlying searches that was owned by the user to be disabled.

ben_leung
Builder

The saved search is shared at the app level, with read access to all roles. Other roles can run the | savedsearch command without getting the error.

ben_leung
Builder

I have ran the saved search command using an admin role user and was successful. I created a new account with the same role as the user that owns this search and has it scheduled. It also ran successful. Running it as the owner seems to be causing the error.

Please let me know how I can get this resolved.

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...