<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: After upgrading from Splunk 6.2.x to 6.3.0, why are scheduled searches by users not accessible to others? &amp;quot;The view you requested could not be found.&amp;quot; in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/After-upgrading-from-Splunk-6-2-x-to-6-3-0-why-are-scheduled/m-p/227963#M4669</link>
    <description>&lt;P&gt;have not yet got this to work properly by adding the "command " in all stanzas the splunk/etc/system/local/alert_action.conf. still default says $results.url$.&lt;BR /&gt;
Reporting here when i have something working in case anyone else has the same problem&lt;/P&gt;</description>
    <pubDate>Thu, 19 Nov 2015 09:46:21 GMT</pubDate>
    <dc:creator>nirmah</dc:creator>
    <dc:date>2015-11-19T09:46:21Z</dc:date>
    <item>
      <title>After upgrading from Splunk 6.2.x to 6.3.0, why are scheduled searches by users not accessible to others? "The view you requested could not be found."</title>
      <link>https://community.splunk.com/t5/Reporting/After-upgrading-from-Splunk-6-2-x-to-6-3-0-why-are-scheduled/m-p/227961#M4667</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;When accessing recent runs of searches by link in the form of:&lt;BR /&gt;
http_//&lt;STRONG&gt;splunkserver&lt;/STRONG&gt;/sv-SE/app/&lt;STRONG&gt;appname&lt;/STRONG&gt;/@go?sid=scheduler_&lt;STRONG&gt;username&lt;/STRONG&gt;_&lt;STRONG&gt;identifier&lt;/STRONG&gt;-at-&lt;STRONG&gt;time&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Example: user john doe created the scheduled search and the link to get to it is as follows:&lt;BR /&gt;
http_//splunkserver.se/sv-SE/app/myapp/@go?sid=scheduler_johndoe_YXZhbnphLXN1cnZlaWxsYW5jZQ__RMD5f9dd4cd6d8829f68_at_1447675200_77841&lt;/P&gt;

&lt;P&gt;All users other than admin user and the user who scheduled the search are faced with this message following the link:&lt;/P&gt;

&lt;P&gt;"&lt;STRONG&gt;The view you requested could not be found.&lt;/STRONG&gt;"&lt;/P&gt;

&lt;P&gt;The access is made within the TTL (since it works for john doe) and I think I have full read rights on all that has tried accessing the search.&lt;/P&gt;

&lt;P&gt;I have until now not found an answer to this and I think this appeared when upgrading from 6.2.x to 6.3.0 recently.&lt;/P&gt;

&lt;P&gt;Thanks in advance!&lt;BR /&gt;
/Per&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 07:52:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/After-upgrading-from-Splunk-6-2-x-to-6-3-0-why-are-scheduled/m-p/227961#M4667</guid>
      <dc:creator>nirmah</dc:creator>
      <dc:date>2020-09-29T07:52:31Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading from Splunk 6.2.x to 6.3.0, why are scheduled searches by users not accessible to others? "The view you requested could not be found."</title>
      <link>https://community.splunk.com/t5/Reporting/After-upgrading-from-Splunk-6-2-x-to-6-3-0-why-are-scheduled/m-p/227962#M4668</link>
      <description>&lt;P&gt;I found the answer myself!&lt;/P&gt;

&lt;P&gt;In accordance to &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.3.1/Report/Schedulereports"&gt;http://docs.splunk.com/Documentation/Splunk/6.3.1/Report/Schedulereports&lt;/A&gt; the &lt;STRONG&gt;results.url&lt;/STRONG&gt; is now deprecated and and reccomends use of &lt;STRONG&gt;results_link&lt;/STRONG&gt; instead.&lt;/P&gt;

&lt;P&gt;Don't know if this should have been taken care of by the migration or what but alert_actions.conf still says that the $results.url$ are passed to scripts etc.&lt;/P&gt;

&lt;P&gt;So if anyone else has a problem with this, change results.url to results_link and it'll work. &lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2015 08:56:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/After-upgrading-from-Splunk-6-2-x-to-6-3-0-why-are-scheduled/m-p/227962#M4668</guid>
      <dc:creator>nirmah</dc:creator>
      <dc:date>2015-11-19T08:56:46Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading from Splunk 6.2.x to 6.3.0, why are scheduled searches by users not accessible to others? "The view you requested could not be found."</title>
      <link>https://community.splunk.com/t5/Reporting/After-upgrading-from-Splunk-6-2-x-to-6-3-0-why-are-scheduled/m-p/227963#M4669</link>
      <description>&lt;P&gt;have not yet got this to work properly by adding the "command " in all stanzas the splunk/etc/system/local/alert_action.conf. still default says $results.url$.&lt;BR /&gt;
Reporting here when i have something working in case anyone else has the same problem&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2015 09:46:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/After-upgrading-from-Splunk-6-2-x-to-6-3-0-why-are-scheduled/m-p/227963#M4669</guid>
      <dc:creator>nirmah</dc:creator>
      <dc:date>2015-11-19T09:46:21Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading from Splunk 6.2.x to 6.3.0, why are scheduled searches by users not accessible to others? "The view you requested could not be found."</title>
      <link>https://community.splunk.com/t5/Reporting/After-upgrading-from-Splunk-6-2-x-to-6-3-0-why-are-scheduled/m-p/227964#M4670</link>
      <description>&lt;P&gt;for some reason the $results_link$ and $results.url$ produce the same (non functioning) link.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2015 11:25:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/After-upgrading-from-Splunk-6-2-x-to-6-3-0-why-are-scheduled/m-p/227964#M4670</guid>
      <dc:creator>nirmah</dc:creator>
      <dc:date>2015-11-19T11:25:48Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading from Splunk 6.2.x to 6.3.0, why are scheduled searches by users not accessible to others? "The view you requested could not be found."</title>
      <link>https://community.splunk.com/t5/Reporting/After-upgrading-from-Splunk-6-2-x-to-6-3-0-why-are-scheduled/m-p/227965#M4671</link>
      <description>&lt;P&gt;After more digging i find that I hit some 403 when getting the search under the hood.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Nov 2015 09:14:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/After-upgrading-from-Splunk-6-2-x-to-6-3-0-why-are-scheduled/m-p/227965#M4671</guid>
      <dc:creator>nirmah</dc:creator>
      <dc:date>2015-11-20T09:14:50Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading from Splunk 6.2.x to 6.3.0, why are scheduled searches by users not accessible to others? "The view you requested could not be found."</title>
      <link>https://community.splunk.com/t5/Reporting/After-upgrading-from-Splunk-6-2-x-to-6-3-0-why-are-scheduled/m-p/227966#M4672</link>
      <description>&lt;P&gt;Was this ever resolved?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Dec 2015 19:34:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/After-upgrading-from-Splunk-6-2-x-to-6-3-0-why-are-scheduled/m-p/227966#M4672</guid>
      <dc:creator>SplunkShawnCt</dc:creator>
      <dc:date>2015-12-14T19:34:15Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading from Splunk 6.2.x to 6.3.0, why are scheduled searches by users not accessible to others? "The view you requested could not be found."</title>
      <link>https://community.splunk.com/t5/Reporting/After-upgrading-from-Splunk-6-2-x-to-6-3-0-why-are-scheduled/m-p/227967#M4673</link>
      <description>&lt;P&gt;I can totally reproduce this bug.&lt;/P&gt;

&lt;P&gt;1) using Splunk 6.3.1 have an Admin user create a savedsearch/alert.&lt;BR /&gt;
2) Change the permissions on the saved search so that all can read and you can put the app in "All Apps".&lt;BR /&gt;
3) Modify search to send mail to a Power user and an Admin user&lt;BR /&gt;
4) The Admin user can see the content. The Power user will get "The view you requested could not be found."&lt;/P&gt;

&lt;P&gt;I opened a case yesterday with Splunk about this. I believe also that it used to work and is likely a 6.2-&amp;gt;6.3 bug.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2016 04:50:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/After-upgrading-from-Splunk-6-2-x-to-6-3-0-why-are-scheduled/m-p/227967#M4673</guid>
      <dc:creator>burwell</dc:creator>
      <dc:date>2016-01-15T04:50:24Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading from Splunk 6.2.x to 6.3.0, why are scheduled searches by users not accessible to others? "The view you requested could not be found."</title>
      <link>https://community.splunk.com/t5/Reporting/After-upgrading-from-Splunk-6-2-x-to-6-3-0-why-are-scheduled/m-p/227968#M4674</link>
      <description>&lt;P&gt;Update: I tried on Splunk 6.3.2 and the problem is fixed.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2016 19:31:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/After-upgrading-from-Splunk-6-2-x-to-6-3-0-why-are-scheduled/m-p/227968#M4674</guid>
      <dc:creator>burwell</dc:creator>
      <dc:date>2016-01-15T19:31:08Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading from Splunk 6.2.x to 6.3.0, why are scheduled searches by users not accessible to others? "The view you requested could not be found."</title>
      <link>https://community.splunk.com/t5/Reporting/After-upgrading-from-Splunk-6-2-x-to-6-3-0-why-are-scheduled/m-p/227969#M4675</link>
      <description>&lt;P&gt;Looks like you are hitting a known bug (SPL-108433), which has been addressed in maintenance release 6.3.2 and higher:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.3.2/ReleaseNotes/6.3.2"&gt;http://docs.splunk.com/Documentation/Splunk/6.3.2/ReleaseNotes/6.3.2&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2016 19:59:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/After-upgrading-from-Splunk-6-2-x-to-6-3-0-why-are-scheduled/m-p/227969#M4675</guid>
      <dc:creator>splunkIT</dc:creator>
      <dc:date>2016-01-15T19:59:43Z</dc:date>
    </item>
  </channel>
</rss>

