Dashboards & Visualizations

Could not create search message on dashboard panels

siva_cg
Path Finder

Hi Team,

We have a distributed environment with Search Head and Indexers clustered running on 6.5.2.

We are facing issues while running dashboards throwing errors "Could not create search" on few dashboard panels. This is being regularly (but not for all users). We do have some dependent panels and tags being used for time ranges. Will these tags cause some issues while running dashboards?

Could you please help in resolving this issue? Thanks in advance.

0 Karma

niketn
Legend

@siva_cg, following are some of your options:

  • Increase number of concurrent searches per user based on your Splunk System configuration.
  • Reduce number of searches in dashboard using post-processing.
  • Try to get rid of real-time searches and use specific panel search refresh.
  • Use saved searches to display results in dashboard.
____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

deepashri_123
Motivator

Hey siva_cg ,

This problem can be based on role access, If the role for the user has less concurrent_searches capability then this error might occur.
Refer the link below:
http://docs.splunk.com/Documentation/Splunk/latest/Security/Rolesandcapabilities

Hope this helps!!

0 Karma

RogerMay
Engager

The problem is that a full browser refresh is required to get rid of the "Could not create search" message, i.e. the built in panel refresh and dashboard level refresh do not clear the message.

0 Karma

dantimola
Communicator

Have you fixed this issue? I got the same issue.

0 Karma

dionrivera
Communicator

FYI, adding the search and rtsearch capabilities to my role fixed this issue for me.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...