Dashboards & Visualizations

Error fetching saved searches

dvg06
Path Finder

hi Splunkers,

I have a dashboard with refresh configured as 120, and most of the panels gets data from saved searches.

Eg:

<search ref="ReportName"></search> 

I see "Error fetching saved searches" multiple times a day and for multiple panels.
I initially thought that the issue is with TTL configs for savedsearches, hence updated dispatch.ttl to 4p, and now can see that at any point of time, 4 results of these savedsearches are retained.
Any idea why the panels throws "Error fetching saved searches"?

Tags (1)

RogerMay
Engager

Hi, did you get a resolution for this issue? I have exactly the same problem,Hi, did you manage to resolve this issue? I have exactly the same problem....

0 Karma

dvg06
Path Finder

When the dashboard refresh, it will contact the captain to get the latest sid and then get the result from the local dispatch directory with the returned sid by captain. The problem seems to be caused by the intermittently failed of replicated search result to search head member.

0 Karma

RogerMay
Engager

Hi, did you get a resolution to this issue? I have exactly the same problem

0 Karma

dvg06
Path Finder

hi @RogerMay

No, I have raised a case with splunk support and they are still investigating.

0 Karma

dinesh_cemad
Explorer

Same here.
A browser refresh fixes the problem but not very useful since we have big TVs to monitor the dashboards.

0 Karma

iamarkaprabha
Contributor

can you share the splunkd.log

0 Karma

dvg06
Path Finder

hi @iamarkaprabha

I do not see any messages relevant in splunkd.log. I did a search for app name, dashboard name, panel name, saved search name but was not able to find anything useful.
Please let me know what component in splunkd I should be looking at?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...