Dashboards & Visualizations

Could not create search message on dashboard panels

siva_cg
Path Finder

Hi Team,

We have a distributed environment with Search Head and Indexers clustered running on 6.5.2.

We are facing issues while running dashboards throwing errors "Could not create search" on few dashboard panels. This is being regularly (but not for all users). We do have some dependent panels and tags being used for time ranges. Will these tags cause some issues while running dashboards?

Could you please help in resolving this issue? Thanks in advance.

0 Karma

niketn
Legend

@siva_cg, following are some of your options:

  • Increase number of concurrent searches per user based on your Splunk System configuration.
  • Reduce number of searches in dashboard using post-processing.
  • Try to get rid of real-time searches and use specific panel search refresh.
  • Use saved searches to display results in dashboard.
____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

deepashri_123
Motivator

Hey siva_cg ,

This problem can be based on role access, If the role for the user has less concurrent_searches capability then this error might occur.
Refer the link below:
http://docs.splunk.com/Documentation/Splunk/latest/Security/Rolesandcapabilities

Hope this helps!!

0 Karma

RogerMay
Engager

The problem is that a full browser refresh is required to get rid of the "Could not create search" message, i.e. the built in panel refresh and dashboard level refresh do not clear the message.

0 Karma

dantimola
Communicator

Have you fixed this issue? I got the same issue.

0 Karma

dionrivera
Path Finder

FYI, adding the search and rtsearch capabilities to my role fixed this issue for me.

0 Karma
Get Updates on the Splunk Community!

Streamline Data Ingestion With Deployment Server Essentials

REGISTER NOW!Every day the list of sources Admins are responsible for gets bigger and bigger, often making the ...

Remediate Threats Faster and Simplify Investigations With Splunk Enterprise Security ...

REGISTER NOW!Join us for a Tech Talk around our latest release of Splunk Enterprise Security 7.2! We’ll walk ...

Introduction to Splunk AI

WATCH NOWHow are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. ...