Hi,
In a dashboard i have added a panel and used Report instead of an inline search to populate data. But it keeps complaining that it could not find the saved search. When i actually verify manually it is there. do you know what could be the reason for this?
Have you checked the xml? I am currently having this same issue and saw that the xml is missing. I have no idea how it got deleted but without that I don't think the search will be able to run. Hope this helps.
your search query
In my case it was the use of /
in the report name as in Origin hits/day (-7days)
. This is a bug in Splunk. If you don't have a /
look for another character that could be throwing it off for just panel usage.
This is my exact issue. Good catch. Thank you!
Thanks for finding this out.
Ran into the same problem and probably would not have figured it out myself.
Interesting variation I had on this: it worked fine when accessing splunk with a short hostname (eg: splunk:8000) and I only got the error when using a fully qualified domain name (eg: splunk.my.domain.org:8000).
Have you checked the permissions of that saved search.
http://docs.splunk.com/Documentation/ODBC/1.0.1/UseODBC/Savedsearchnotfoundmessage .. could this be possibly related to your issue?
yes it is public