Dashboards & Visualizations

Dashboard Studio: "Search <id> not found. the search may have been cancelled while there are still subscribers"

gciotto
Loves-to-Learn Lots

Hi,

I am using Dashboard Studio to build my dashboard. When loading a timechart containing a small set of events ( ~200), I frequently get a "Search <id> not found. the search may have been cancelled while there are still subscribers" error and the chart is not rendered accordingly.  It does work if I click on the chart's refresh button, but that is a very bad user experience.

The timechart's data source follows the pattern below. My dashboard has two of them.

 

index = <index> sourcetype = <sourcetype> source = <source> host = <host>
| multikv fields <fieldA> <fieldB> filter <condition>
| timechart avg(fieldA)  avg(fieldB)

 

Best regards,

Gustavo

Labels (2)
0 Karma

twollenslegel_s
Splunk Employee
Splunk Employee

This is a known issue;  Splunk is currently working on improving this issue, no ETA, but expect to see improvements in a version > 10.0. 

0 Karma

emlin_charly
Explorer

This is due to issues with load balancers sitting in front of the hosts. Check the stickiness of the load balancers. Accessing a SH member directly should solve it.

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@gciotto - Ask your Splunk admins if there is a resource-limit or time-limit imposed at the user or role level, that could be canceling the searching. (With Workload Rules)

 

I hope this helps!! Upvote if it does!!!

0 Karma

gciotto
Loves-to-Learn Lots

Hi @VatsalJagani , thank you for your comment.

The only solution that we found was to migrate our dashboards to the classic mode. The exact same queries worked fine in this mode.

Gustavo

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

Weird behavior though!!! But great it worked for you!!! Kindly accept your answer for future community users.

 

Kindly upvote if you find my comment helpful!!!

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...