Security

Error in 'SearchParser': Missing a search command before ' '.

alenseb
Communicator

Hi,

I am trying to access one of my saved Searches, but this error is shown all of a sudden.
My syntax is correct as the same code was working sometime back.
Is this a product bug?

Please help.

Thanks!!

0 Karma

ryonts
Explorer

I discovered today that after modifying a saved search to format it for better readability, this error showed up. The problem was that in formatting it, I added some CRLF characters. Afterwards, the error showed up. For some reason, CRLF are NOT ignored, but affect the search string. Hopefully this can help your situation. (I HATE unformatted search strings, too difficult to read when all jumbled up!)

0 Karma

ryonts
Explorer

I discovered today that after modifying a saved search to format it for better readability, this error showed up. The problem was that in formatting it, I added some CRLF characters. Afterwards, the error showed up. For some reason, CRLF are NOT ignored, but affect the search string. Hopefully this can help your situation. (I HATE unformatted search strings, too difficult to read when all jumbled up!)

MarioM
Motivator

to get help you need to give more infos:
-post the complete search
-splunk version
-permissions of the searches/report/dashboards/apps...

0 Karma

alenseb
Communicator

Just read somewhere for these of errors, you have to re-install.
Any idea on why?

0 Karma

alenseb
Communicator

i haven't changed anything.

0 Karma

MuS
Legend

so what did change since it last was working?

0 Karma

alenseb
Communicator

The search works just fine, but when i search as a | savedsearch i get the error.

Also the same SavedSearch command was working fine sometime back.

0 Karma

lguinn2
Legend

We need to see the actual search text. Go to the Manager and edit the saved search. Copy the search into a comment.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...