Dashboards & Visualizations

Could not create search message on dashboard panels

siva_cg
Path Finder

Hi Team,

We have a distributed environment with Search Head and Indexers clustered running on 6.5.2.

We are facing issues while running dashboards throwing errors "Could not create search" on few dashboard panels. This is being regularly (but not for all users). We do have some dependent panels and tags being used for time ranges. Will these tags cause some issues while running dashboards?

Could you please help in resolving this issue? Thanks in advance.

0 Karma

niketn
Legend

@siva_cg, following are some of your options:

  • Increase number of concurrent searches per user based on your Splunk System configuration.
  • Reduce number of searches in dashboard using post-processing.
  • Try to get rid of real-time searches and use specific panel search refresh.
  • Use saved searches to display results in dashboard.
____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

deepashri_123
Motivator

Hey siva_cg ,

This problem can be based on role access, If the role for the user has less concurrent_searches capability then this error might occur.
Refer the link below:
http://docs.splunk.com/Documentation/Splunk/latest/Security/Rolesandcapabilities

Hope this helps!!

0 Karma

RogerMay
Engager

The problem is that a full browser refresh is required to get rid of the "Could not create search" message, i.e. the built in panel refresh and dashboard level refresh do not clear the message.

0 Karma

dantimola
Communicator

Have you fixed this issue? I got the same issue.

0 Karma

dionrivera
Communicator

FYI, adding the search and rtsearch capabilities to my role fixed this issue for me.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...