<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic When creating ES rules I get this error - &amp;quot;Search could not be updated: Argument &amp;quot;schedule_priority&amp;quot; is not supported by this handler.&amp;quot; in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/When-creating-ES-rules-I-get-this-error-quot-Search-could-not-be/m-p/321134#M2958</link>
    <description>&lt;P&gt;I cannot find any literature on it or an explanation. Does anybody recognize this and know how to remedy?&lt;/P&gt;</description>
    <pubDate>Fri, 19 Jan 2018 17:42:58 GMT</pubDate>
    <dc:creator>bscavotto</dc:creator>
    <dc:date>2018-01-19T17:42:58Z</dc:date>
    <item>
      <title>When creating ES rules I get this error - "Search could not be updated: Argument "schedule_priority" is not supported by this handler."</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/When-creating-ES-rules-I-get-this-error-quot-Search-could-not-be/m-p/321134#M2958</link>
      <description>&lt;P&gt;I cannot find any literature on it or an explanation. Does anybody recognize this and know how to remedy?&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2018 17:42:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/When-creating-ES-rules-I-get-this-error-quot-Search-could-not-be/m-p/321134#M2958</guid>
      <dc:creator>bscavotto</dc:creator>
      <dc:date>2018-01-19T17:42:58Z</dc:date>
    </item>
    <item>
      <title>Re: When creating ES rules I get this error - "Search could not be updated: Argument "schedule_priority" is not supported by this handler."</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/When-creating-ES-rules-I-get-this-error-quot-Search-could-not-be/m-p/321135#M2959</link>
      <description>&lt;P&gt;i am also getting the same error while creating a correlation search. Infact i get the same error when i try to create an alert in Splunk enterprise suite. &lt;BR /&gt;
I think it's because of some sort of issue with the Scheduler. Just thinking out loud.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 09:24:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/When-creating-ES-rules-I-get-this-error-quot-Search-could-not-be/m-p/321135#M2959</guid>
      <dc:creator>qbolbk59</dc:creator>
      <dc:date>2019-03-26T09:24:13Z</dc:date>
    </item>
    <item>
      <title>Re: When creating ES rules I get this error - "Search could not be updated: Argument "schedule_priority" is not supported by this handler."</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/When-creating-ES-rules-I-get-this-error-quot-Search-could-not-be/m-p/321136#M2960</link>
      <description>&lt;P&gt;Whats your version of Splunk Core and ES?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 09:59:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/When-creating-ES-rules-I-get-this-error-quot-Search-could-not-be/m-p/321136#M2960</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2019-03-26T09:59:40Z</dc:date>
    </item>
    <item>
      <title>Re: When creating ES rules I get this error - "Search could not be updated: Argument "schedule_priority" is not supported by this handler."</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/When-creating-ES-rules-I-get-this-error-quot-Search-could-not-be/m-p/321137#M2961</link>
      <description>&lt;P&gt;@lakshman239 I am running Splunk 7.2.1 with ES 5.2&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 10:42:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/When-creating-ES-rules-I-get-this-error-quot-Search-could-not-be/m-p/321137#M2961</guid>
      <dc:creator>qbolbk59</dc:creator>
      <dc:date>2019-03-26T10:42:43Z</dc:date>
    </item>
    <item>
      <title>Re: When creating ES rules I get this error - "Search could not be updated: Argument "schedule_priority" is not supported by this handler."</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/When-creating-ES-rules-I-get-this-error-quot-Search-could-not-be/m-p/321138#M2962</link>
      <description>&lt;P&gt;ok, I am on 7.0.3 with ES 5.1.1 still and don't see any issue. This comes from schedule_priority setting in the savedsearches.conf . Could you try the following?&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;As admin user, can you try to edit (any dummy changes will do) any of the correlation searches that comes with ES? Are you seeing any errors when saving it?&lt;/LI&gt;
&lt;LI&gt;do the above step 1 as non-admin user and are you seeing any diff behaviour? &lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;This could indicate any issues with permissions/roles/capabilities to user.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 12:10:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/When-creating-ES-rules-I-get-this-error-quot-Search-could-not-be/m-p/321138#M2962</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2019-03-26T12:10:14Z</dc:date>
    </item>
  </channel>
</rss>

