Dashboards & Visualizations

Could not create search message on dashboard panels

siva_cg
Path Finder

Hi Team,

We have a distributed environment with Search Head and Indexers clustered running on 6.5.2.

We are facing issues while running dashboards throwing errors "Could not create search" on few dashboard panels. This is being regularly (but not for all users). We do have some dependent panels and tags being used for time ranges. Will these tags cause some issues while running dashboards?

Could you please help in resolving this issue? Thanks in advance.

0 Karma

niketn
Legend

@siva_cg, following are some of your options:

  • Increase number of concurrent searches per user based on your Splunk System configuration.
  • Reduce number of searches in dashboard using post-processing.
  • Try to get rid of real-time searches and use specific panel search refresh.
  • Use saved searches to display results in dashboard.
____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

deepashri_123
Motivator

Hey siva_cg ,

This problem can be based on role access, If the role for the user has less concurrent_searches capability then this error might occur.
Refer the link below:
http://docs.splunk.com/Documentation/Splunk/latest/Security/Rolesandcapabilities

Hope this helps!!

0 Karma

RogerMay
Engager

The problem is that a full browser refresh is required to get rid of the "Could not create search" message, i.e. the built in panel refresh and dashboard level refresh do not clear the message.

0 Karma

dantimola
Communicator

Have you fixed this issue? I got the same issue.

0 Karma

dionrivera
Communicator

FYI, adding the search and rtsearch capabilities to my role fixed this issue for me.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...