<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Encountered the following error while trying to update: In handler 'savedsearch': Cannot find viewstate with vsid=&amp;quot;XXXXX&amp;quot; while saving the searches? in Security</title>
    <link>https://community.splunk.com/t5/Security/Encountered-the-following-error-while-trying-to-update-In/m-p/242419#M14884</link>
    <description>&lt;P&gt;I cannot tell you how it got broken, but to fix it, just go to CLI on your search head, find the associated &lt;CODE&gt;savedsearches.conf&lt;/CODE&gt; file, edit it, find the associated search stanza and delete the &lt;CODE&gt;vsid=&lt;/CODE&gt; line.&lt;/P&gt;</description>
    <pubDate>Fri, 01 Jul 2016 12:42:51 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2016-07-01T12:42:51Z</dc:date>
    <item>
      <title>Encountered the following error while trying to update: In handler 'savedsearch': Cannot find viewstate with vsid="XXXXX" while saving the searches?</title>
      <link>https://community.splunk.com/t5/Security/Encountered-the-following-error-while-trying-to-update-In/m-p/242418#M14883</link>
      <description>&lt;P&gt;I have got ticket for a user facing the above mentioned problem for quiet some times, when user is trying to save the saved search reports from settings -search &amp;amp; reports -search name - XXXX , he is getting the above mentioned error, but he could save other reports with his name.&lt;BR /&gt;
  Even as a admin user when tried to save the report it throws the same error.&lt;/P&gt;

&lt;P&gt;I had followed this steps to trouble shoots but did not work out.&lt;BR /&gt;
1) Checked the permission level and modified to read/write to this user for this particular app -search but no luck.&lt;BR /&gt;
2) I have verified the &lt;STRONG&gt;savedsearch.conf&lt;/STRONG&gt; and &lt;STRONG&gt;viewstate.conf&lt;/STRONG&gt; and could not find the  search details &amp;amp; vsid="xxxx" information. So created the saved search with same  details with vsid="xxxx" and restarted, but no luck.&lt;BR /&gt;
3) under this path  /&lt;STRONG&gt;opt/splunk/etc/apps/search/metadata/local.meta&lt;/STRONG&gt; , I could not see the search information or the owner information. should I need to create this stanza in local.meta&lt;/P&gt;

&lt;P&gt;[savedsearches/Cisco]&lt;BR /&gt;
modtime = 1342788232.129847000 - What is this stand for ? &lt;BR /&gt;
version = 4.3.1 &lt;BR /&gt;
owner = xxxx &lt;/P&gt;

&lt;P&gt;[viewstates/flashtimeline%3Ah4v9ekgh]&lt;BR /&gt;
owner = nobody&lt;BR /&gt;
modtime = 1342788211.984089000&lt;BR /&gt;
version = 4.3.1 -- Is this a splunk app version ? &lt;BR /&gt;
export = system&lt;/P&gt;

&lt;P&gt;Details - &lt;BR /&gt;
Splunk version 6.0.3 version &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;splunk_access.log details&lt;/STRONG&gt; : &lt;/P&gt;

&lt;P&gt;127.0.0.1 - xxxxx [01/Jul/2016:05:16:58.635 -0400] "GET /services HTTP/1.0" 200 8371 - - - 2ms&lt;BR /&gt;
127.0.0.1 - xxxxx [01/Jul/2016:05:16:58.642 -0400] "GET /servicesNS/xxxxx/search/data/ui/manager?count=-1 HTTP/1.0" 200 510940 - - - 58ms&lt;BR /&gt;
127.0.0.1 - xxxxx [01/Jul/2016:05:16:58.884 -0400] "GET /servicesNS/xxxx/search/saved/searches/Cisco%20-%20Critical%20and%20Alert%20%28ASA%20only%29 HTTP/1.0" 200 27960 - - - 28ms&lt;BR /&gt;
127.0.0.1 - xxxxx [01/Jul/2016:05:16:58.921 -0400] "GET /servicesNS/xxxx/search/saved/searches/Cisco%20-%20Critical%20and%20Alert%20%28ASA%20only%29 HTTP/1.0" 200 27960 - - - 21ms&lt;BR /&gt;
127.0.0.1 - xxxx [01/Jul/2016:05:16:58.947 -0400] "POST /servicesNS/xxxx/search/saved/searches/Cisco%20-%20Critical%20and%20Alert%20%28ASA%20only%29 HTTP/1.0" 400 186 - - - 7ms&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;splunkd.log details -&lt;/STRONG&gt; &lt;BR /&gt;
07-01-2016 05:16:58.954 -0400 ERROR SavedSearchAdminHandler - Cannot find viewstate with vsid="xxxx"&lt;/P&gt;

&lt;P&gt;Please do let me know how to fix this issue.&lt;BR /&gt;
thanks in advance &lt;/P&gt;</description>
      <pubDate>Fri, 01 Jul 2016 10:10:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Encountered-the-following-error-while-trying-to-update-In/m-p/242418#M14883</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2016-07-01T10:10:01Z</dc:date>
    </item>
    <item>
      <title>Re: Encountered the following error while trying to update: In handler 'savedsearch': Cannot find viewstate with vsid="XXXXX" while saving the searches?</title>
      <link>https://community.splunk.com/t5/Security/Encountered-the-following-error-while-trying-to-update-In/m-p/242419#M14884</link>
      <description>&lt;P&gt;I cannot tell you how it got broken, but to fix it, just go to CLI on your search head, find the associated &lt;CODE&gt;savedsearches.conf&lt;/CODE&gt; file, edit it, find the associated search stanza and delete the &lt;CODE&gt;vsid=&lt;/CODE&gt; line.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jul 2016 12:42:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Encountered-the-following-error-while-trying-to-update-In/m-p/242419#M14884</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2016-07-01T12:42:51Z</dc:date>
    </item>
    <item>
      <title>Re: Encountered the following error while trying to update: In handler 'savedsearch': Cannot find viewstate with vsid="XXXXX" while saving the searches?</title>
      <link>https://community.splunk.com/t5/Security/Encountered-the-following-error-while-trying-to-update-In/m-p/242420#M14885</link>
      <description>&lt;P&gt;thanks Woodcock, In the search head under the path  /opt/splunk/etc/apps/search/local/savedsearches.conf, did not find any stanza related to this saved search. I had checked the same in the viewstates.conf but nothing was related to this search. So I had created the same search query and saved it in the savedsearches.conf and corresponding viewstates.conf,  finally restarted the service but still its throwing the same error.&lt;/P&gt;

&lt;P&gt;[Cisco ]&lt;BR /&gt;
action.email.inline = 1&lt;BR /&gt;
alert.digest_mode = True&lt;BR /&gt;
alert.suppress = 0&lt;BR /&gt;
alert.track = 0&lt;BR /&gt;
cron_schedule = * * * * *&lt;BR /&gt;
dispatch.latest_time = now&lt;BR /&gt;
displayview = flashtimeline&lt;BR /&gt;
request.ui_dispatch_view = flashtimeline&lt;BR /&gt;
search = source="/var/log/syslog_info" _raw=&lt;EM&gt;DUAL-3-SIA&lt;/EM&gt; _raw!=&lt;EM&gt;INDIVIDUAL&lt;/EM&gt; earliest=-30d@h | table _time, _raw | sort -_time&lt;BR /&gt;
vsid = xxxx&lt;/P&gt;

&lt;P&gt;Viewstates.conf -&lt;/P&gt;

&lt;P&gt;[flashtimeline:xxxx]  - &lt;STRONG&gt;Same Vsid value given in the savedsearches.conf&lt;/STRONG&gt; &lt;BR /&gt;
AxisScaleFormatter_0_18_0.default = ""&lt;BR /&gt;
ButtonSwitcher_0_8_0.selected = splIcon-results-table&lt;BR /&gt;
ChartTypeFormatter_0_13_0.default = column&lt;BR /&gt;
Count_0_7_1.default = 50&lt;BR /&gt;
DataOverlay_0_13_0.dataOverlayMode = none&lt;BR /&gt;
DataOverlay_0_13_0.default = none&lt;BR /&gt;
FieldPicker_0_5_1.fields = host,sourcetype,source,User&lt;BR /&gt;
FieldPicker_0_5_1.sidebarDisplay = True&lt;BR /&gt;
FlashTimeline_0_4_1.height = 94px&lt;BR /&gt;
FlashTimeline_0_4_1.minimized = False&lt;BR /&gt;
JSChart_0_13_1.height = 300px&lt;BR /&gt;
LegendFormatter_0_19_0.default = right&lt;BR /&gt;
MaxLines_0_13_0.default = 10&lt;BR /&gt;
MaxLines_0_13_0.maxLines = 10&lt;BR /&gt;
NullValueFormatter_0_18_0.default = gaps&lt;BR /&gt;
RowNumbers_0_12_0.default = true&lt;BR /&gt;
RowNumbers_0_12_0.displayRowNumbers = true&lt;BR /&gt;
RowNumbers_1_12_0.default = true&lt;BR /&gt;
RowNumbers_1_12_0.displayRowNumbers = true&lt;BR /&gt;
Segmentation_0_14_0.default = full&lt;BR /&gt;
Segmentation_0_14_0.segmentation = full&lt;BR /&gt;
SoftWrap_0_11_0.enable = True&lt;BR /&gt;
SplitModeFormatter_0_17_0.default = false&lt;BR /&gt;
StackModeFormatter_0_16_0.default = default&lt;BR /&gt;
YAxisRangeMaximumFormatter_0_17_0.default = ""&lt;BR /&gt;
YAxisRangeMinimumFormatter_0_16_0.default = ""&lt;/P&gt;

&lt;P&gt;please do let us know is any other way we can resolve this problem.  Even in the /opt/splunk/etc/apps/search/metadata/local.meta, I could not see the stanza related to this saved search. &lt;BR /&gt;
thanks in Advance. &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:05:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Encountered-the-following-error-while-trying-to-update-In/m-p/242420#M14885</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2020-09-29T10:05:45Z</dc:date>
    </item>
    <item>
      <title>Re: Encountered the following error while trying to update: In handler 'savedsearch': Cannot find viewstate with vsid="XXXXX" while saving the searches?</title>
      <link>https://community.splunk.com/t5/Security/Encountered-the-following-error-while-trying-to-update-In/m-p/242421#M14886</link>
      <description>&lt;P&gt;There are 2 possible &lt;CODE&gt;savedsearches.conf&lt;/CODE&gt; file locations depending on the &lt;CODE&gt;Permission&lt;/CODE&gt; of the search.  For &lt;CODE&gt;Private&lt;/CODE&gt; permission, it is &lt;CODE&gt;$SPLUNK_HOME/etc/users/YourUser/YourApp/local/savedsearches.conf&lt;/CODE&gt;.  For &lt;CODE&gt;App&lt;/CODE&gt; and  &lt;CODE&gt;Global&lt;/CODE&gt; permission, it is &lt;CODE&gt;$SPLUNK_HOME/etc/apps/YourApp/local/savedsearches.conf&lt;/CODE&gt;.  You have to find the correct search and delete the broken viewstate (like I said in the beginning).&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jul 2016 19:05:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Encountered-the-following-error-while-trying-to-update-In/m-p/242421#M14886</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2016-07-04T19:05:10Z</dc:date>
    </item>
    <item>
      <title>Re: Encountered the following error while trying to update: In handler 'savedsearch': Cannot find viewstate with vsid="XXXXX" while saving the searches?</title>
      <link>https://community.splunk.com/t5/Security/Encountered-the-following-error-while-trying-to-update-In/m-p/242422#M14887</link>
      <description>&lt;P&gt;thank Woodcock, You are right, I have checked the path /opt/splunk/etc/users/username/search/local/savedsearches.conf and deleted the VSID = XXXX from the saved search.  I have got this above information from file system pooling not in the search heads. After finding the correct search from the savedsearches.conf file, deleted the  VSID =xxxx stanza from the search and restarted the splunk service in the search heads. &lt;BR /&gt;
There is no VSID = XXXX in viewstates.conf so did not change any settings. &lt;/P&gt;

&lt;P&gt;Now the user can edit and save the searches from the setting--&amp;gt;search--&amp;gt;reporting--searchAPP--CISCO.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2016 10:28:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Encountered-the-following-error-while-trying-to-update-In/m-p/242422#M14887</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2016-07-05T10:28:04Z</dc:date>
    </item>
  </channel>
</rss>

