<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Display error :Could not create search in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Display-error-Could-not-create-search/m-p/213586#M175987</link>
    <description>&lt;P&gt;I accept that various concurrent search settings can initially cause this problem, HOWEVER, the main issue for me is that even with each panel auto refreshing and the dashboard as a whole auto refreshing, the message does not go away. It is only when the browser is refreshed with an F5 that the search is retried.&lt;/P&gt;</description>
    <pubDate>Thu, 11 Apr 2019 16:04:27 GMT</pubDate>
    <dc:creator>RogerMay</dc:creator>
    <dc:date>2019-04-11T16:04:27Z</dc:date>
    <item>
      <title>Display error :Could not create search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Display-error-Could-not-create-search/m-p/213574#M175975</link>
      <description>&lt;P&gt;create many query in panels, but some panels can display right search result, some can not and display the error:Could not create search .&lt;/P&gt;

&lt;P&gt;I deleted some panels so that all the panels can display right search result.&lt;/P&gt;

&lt;P&gt;So, are there too many query or SPL in my APP?&lt;/P&gt;

&lt;P&gt;By the way,  the error panels were different when run the search each time（error display in which panels are look like random）.&lt;/P&gt;

&lt;P&gt;＜updated＞&lt;BR /&gt;
I change the IE to Chrome then run the search again, everything gonna be OK !&lt;BR /&gt;
Is it bug for splunk ?&lt;BR /&gt;
How to fix it if I have to use IE ?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jan 2017 07:08:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Display-error-Could-not-create-search/m-p/213574#M175975</guid>
      <dc:creator>kavana</dc:creator>
      <dc:date>2017-01-04T07:08:07Z</dc:date>
    </item>
    <item>
      <title>Re: Display error :Could not create search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Display-error-Could-not-create-search/m-p/213575#M175976</link>
      <description>&lt;P&gt;I think you need to check parameters (base_max_searches, max_searches_per_cpu, max_rt_search_multiplier) in file limits.conf in [search] section.&lt;BR /&gt;
&lt;STRONG&gt;Caution&lt;/STRONG&gt;: do not change limits.conf settings unless you know what you are doing.&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.1/Admin/Limitsconf#.5Bsearch.5D" target="_blank"&gt;http://docs.splunk.com/Documentation/Splunk/6.5.1/Admin/Limitsconf#.5Bsearch.5D&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Also read this:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.1/Report/Configurethepriorityofscheduledreports" target="_blank"&gt;http://docs.splunk.com/Documentation/Splunk/6.5.1/Report/Configurethepriorityofscheduledreports&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:15:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Display-error-Could-not-create-search/m-p/213575#M175976</guid>
      <dc:creator>kalianov</dc:creator>
      <dc:date>2020-09-29T12:15:22Z</dc:date>
    </item>
    <item>
      <title>Re: Display error :Could not create search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Display-error-Could-not-create-search/m-p/213576#M175977</link>
      <description>&lt;P&gt;Have you used post processing in your search queries? &lt;BR /&gt;
Are you passing statistically aggregated data or raw events through post processing?&lt;BR /&gt;
Also how many queries are you trying to run?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2017 05:04:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Display-error-Could-not-create-search/m-p/213576#M175977</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2017-01-05T05:04:30Z</dc:date>
    </item>
    <item>
      <title>Re: Display error :Could not create search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Display-error-Could-not-create-search/m-p/213577#M175978</link>
      <description>&lt;P&gt;Thank you so much!&lt;/P&gt;

&lt;P&gt;The default value of  「base_max_searches」 in limits.conf  is 6, I increaseｄ the value(to 100) then all the panels also can be run in IE and no error.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:15:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Display-error-Could-not-create-search/m-p/213577#M175978</guid>
      <dc:creator>kavana</dc:creator>
      <dc:date>2020-09-29T12:15:55Z</dc:date>
    </item>
    <item>
      <title>Re: Display error :Could not create search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Display-error-Could-not-create-search/m-p/213578#M175979</link>
      <description>&lt;P&gt;unfortunately, Just first time to run the searches are OK.&lt;/P&gt;

&lt;P&gt;The error happens again after first time in IE.... &lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2017 05:35:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Display-error-Could-not-create-search/m-p/213578#M175979</guid>
      <dc:creator>kavana</dc:creator>
      <dc:date>2017-01-05T05:35:43Z</dc:date>
    </item>
    <item>
      <title>Re: Display error :Could not create search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Display-error-Could-not-create-search/m-p/213579#M175980</link>
      <description>&lt;P&gt;Sorry,I'm rookie about splunk.&lt;BR /&gt;
How can I distinguish if I used post processing ?&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2017 03:59:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Display-error-Could-not-create-search/m-p/213579#M175980</guid>
      <dc:creator>kavana</dc:creator>
      <dc:date>2017-01-06T03:59:52Z</dc:date>
    </item>
    <item>
      <title>Re: Display error :Could not create search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Display-error-Could-not-create-search/m-p/213580#M175981</link>
      <description>&lt;P&gt;In your &lt;STRONG&gt;&amp;lt;search&amp;gt;&lt;/STRONG&gt; tags do you see &lt;STRONG&gt;id="&amp;lt;SomeSearchName&amp;gt;" and then base="&amp;lt;SomeSearchName&amp;gt;"&lt;/STRONG&gt; ?&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2017 04:16:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Display-error-Could-not-create-search/m-p/213580#M175981</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2017-01-06T04:16:32Z</dc:date>
    </item>
    <item>
      <title>Re: Display error :Could not create search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Display-error-Could-not-create-search/m-p/213581#M175982</link>
      <description>&lt;P&gt;Also check your earliest and latest tags whether there is realtime searh &lt;STRONG&gt;rt&lt;/STRONG&gt; used or not.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2017 04:18:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Display-error-Could-not-create-search/m-p/213581#M175982</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2017-01-06T04:18:07Z</dc:date>
    </item>
    <item>
      <title>Re: Display error :Could not create search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Display-error-Could-not-create-search/m-p/213582#M175983</link>
      <description>&lt;P&gt;There is no  id="" and then base="" in  tags.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2017 05:19:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Display-error-Could-not-create-search/m-p/213582#M175983</guid>
      <dc:creator>kavana</dc:creator>
      <dc:date>2017-01-06T05:19:59Z</dc:date>
    </item>
    <item>
      <title>Re: Display error :Could not create search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Display-error-Could-not-create-search/m-p/213583#M175984</link>
      <description>&lt;P&gt;base_max_searches = 100  is  too  much.&lt;/P&gt;

&lt;P&gt;max_hist_searches =  max_searches_per_cpu x number_of_cpus + base_max_searches&lt;/P&gt;

&lt;P&gt;max_rt_searches = max_rt_search_multiplier x max_hist_searches&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:25:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Display-error-Could-not-create-search/m-p/213583#M175984</guid>
      <dc:creator>kalianov</dc:creator>
      <dc:date>2020-09-29T12:25:54Z</dc:date>
    </item>
    <item>
      <title>Re: Display error :Could not create search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Display-error-Could-not-create-search/m-p/213584#M175985</link>
      <description>&lt;P&gt;This has not helped my situation.  We are not receiving any errors I can find in the logs however routinely receive "Could not create search" in dashboard panels randomly.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2017 16:48:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Display-error-Could-not-create-search/m-p/213584#M175985</guid>
      <dc:creator>Cuyose</dc:creator>
      <dc:date>2017-11-09T16:48:11Z</dc:date>
    </item>
    <item>
      <title>Re: Display error :Could not create search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Display-error-Could-not-create-search/m-p/213585#M175986</link>
      <description>&lt;P&gt;You should check what are the hardware resources of your respective search-head (or maybe you have a single-instance Splunk?) and what are the hardware resources of the machine you are using to display your dashboard (your workstation/notebook/...). "Could not create search" is caused by timeout, and it may have causes on both server and client side.&lt;/P&gt;

&lt;P&gt;On client-side, this may be caused (among other causes) by slow processing in client-side browser. This corresponds to your experience of Chrome suffering less than IE (Chrome is known to be more efficient). Try to display your dashboard on more powerful computer (or at least kill all other applications and browser tabs).&lt;/P&gt;

&lt;P&gt;If the problem is in insufficient resources of the search-head (you should see constantly high CPU load, check your monitoring console), try to reduce the load by reducing the number of concurrent searches (eg. remove some panels) and/or simplyfying your queries. You should also consider upgrading your server hardware.&lt;/P&gt;

&lt;P&gt;Increasing values in limits.conf (as discussed under the other answer) can actually make things worse in such case (it is like bringing even more traffic to a street suffering from regular traffic jams). Tuning the limits is rather complex topic that can not be explained in a short answer here and is affected by many aspects (including your topology etc.). Without good understanding of how Splunk works under the hood, this might be a kind of black magic. Definitely not a thing to experiment with in a production environments.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 08:54:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Display-error-Could-not-create-search/m-p/213585#M175986</guid>
      <dc:creator>eregon</dc:creator>
      <dc:date>2019-04-03T08:54:49Z</dc:date>
    </item>
    <item>
      <title>Re: Display error :Could not create search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Display-error-Could-not-create-search/m-p/213586#M175987</link>
      <description>&lt;P&gt;I accept that various concurrent search settings can initially cause this problem, HOWEVER, the main issue for me is that even with each panel auto refreshing and the dashboard as a whole auto refreshing, the message does not go away. It is only when the browser is refreshed with an F5 that the search is retried.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2019 16:04:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Display-error-Could-not-create-search/m-p/213586#M175987</guid>
      <dc:creator>RogerMay</dc:creator>
      <dc:date>2019-04-11T16:04:27Z</dc:date>
    </item>
  </channel>
</rss>

