Security

Error in 'SearchParser': Missing a search command before ' '.

alenseb
Communicator

Hi,

I am trying to access one of my saved Searches, but this error is shown all of a sudden.
My syntax is correct as the same code was working sometime back.
Is this a product bug?

Please help.

Thanks!!

0 Karma

ryonts
Explorer

I discovered today that after modifying a saved search to format it for better readability, this error showed up. The problem was that in formatting it, I added some CRLF characters. Afterwards, the error showed up. For some reason, CRLF are NOT ignored, but affect the search string. Hopefully this can help your situation. (I HATE unformatted search strings, too difficult to read when all jumbled up!)

0 Karma

ryonts
Explorer

I discovered today that after modifying a saved search to format it for better readability, this error showed up. The problem was that in formatting it, I added some CRLF characters. Afterwards, the error showed up. For some reason, CRLF are NOT ignored, but affect the search string. Hopefully this can help your situation. (I HATE unformatted search strings, too difficult to read when all jumbled up!)

MarioM
Motivator

to get help you need to give more infos:
-post the complete search
-splunk version
-permissions of the searches/report/dashboards/apps...

0 Karma

alenseb
Communicator

Just read somewhere for these of errors, you have to re-install.
Any idea on why?

0 Karma

alenseb
Communicator

i haven't changed anything.

0 Karma

MuS
Legend

so what did change since it last was working?

0 Karma

alenseb
Communicator

The search works just fine, but when i search as a | savedsearch i get the error.

Also the same SavedSearch command was working fine sometime back.

0 Karma

lguinn2
Legend

We need to see the actual search text. Go to the Manager and edit the saved search. Copy the search into a comment.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud’s AI Assistant in Action Series: Analyzing and ...

This is the second post in our Splunk Observability Cloud’s AI Assistant in Action series, in which we look at ...

Elevate Your Organization with Splunk’s Next Platform Evolution

 Thursday, July 10, 2025  |  11AM PDT / 2PM EDT Whether you're managing complex deployments or looking to ...

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...