Dashboards & Visualizations

Could not create search message on dashboard panels

siva_cg
Path Finder

Hi Team,

We have a distributed environment with Search Head and Indexers clustered running on 6.5.2.

We are facing issues while running dashboards throwing errors "Could not create search" on few dashboard panels. This is being regularly (but not for all users). We do have some dependent panels and tags being used for time ranges. Will these tags cause some issues while running dashboards?

Could you please help in resolving this issue? Thanks in advance.

0 Karma

niketn
Legend

@siva_cg, following are some of your options:

  • Increase number of concurrent searches per user based on your Splunk System configuration.
  • Reduce number of searches in dashboard using post-processing.
  • Try to get rid of real-time searches and use specific panel search refresh.
  • Use saved searches to display results in dashboard.
____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

deepashri_123
Motivator

Hey siva_cg ,

This problem can be based on role access, If the role for the user has less concurrent_searches capability then this error might occur.
Refer the link below:
http://docs.splunk.com/Documentation/Splunk/latest/Security/Rolesandcapabilities

Hope this helps!!

0 Karma

RogerMay
Engager

The problem is that a full browser refresh is required to get rid of the "Could not create search" message, i.e. the built in panel refresh and dashboard level refresh do not clear the message.

0 Karma

dantimola
Communicator

Have you fixed this issue? I got the same issue.

0 Karma

dionrivera
Path Finder

FYI, adding the search and rtsearch capabilities to my role fixed this issue for me.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...