Dashboards & Visualizations

In handler 'saved search': Error while dispatching search

yinzs02
Engager

I have a dashboard which include 8 panels. Each panel has a saved search attached to it. Everything worked fine till this morning.

When I load the dashboard, I see a few of those panels loaded fine, but a few others gave this "In handler saved search: Error while dispatching search" alert. I cleared everything under the dispatch directory, but it didn't help.

I googled it, and looks like another user ran into the same issue, and he/she fixed it with the option "Clone to an inline search". It's not necessarily what I wish to do though.

Does anyone know if it's a bug with version 6.1? I upgraded my Splunk from 5 to 6.1 a few weeks ago, and this problem only appeared today.

Thanks for any comments or suggestions.

jkat54
SplunkTrust
SplunkTrust

My guess is that you're running into a max searches limit issue and that your user role isnt allowed to have as many searches running as you' have.

You can open the panel in search, and then use the job inspector to figure out more details related to why the search is failing.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Take a look at the _internal index at the time of the error message for any clues.

0 Karma

the_wolverine
Champion

We are seeing lots of issues like this with our Simple XML dashboards in version 6.0x. Splunk is investigating. They tell us that we need to convert dashboards to HTML as a workaround but we have found that converting to Advanced XML has worked for us -- FYI, Splunk advises against using Advanced XML.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...