Monitoring Splunk

How do I fix: 'litsearch' command: Unable to parse the search: unbalanced parentheses?

Mr_Johnson42
Observer

I'm an end user! It appears to be just my user account. we dont seem to be able to find the answer

When I do any search (such as index="med") I get 
"Error in 'litsearch' command: Unable to parse the search: unbalanced parentheses."

When I go through the logs I was surprised to see that such a simple search resulted in

litsearch (index="med" index=nessus ((source="SI - EZproxy" orig_sourcetype="nessus:scan") OR sourcetype="nessus:scan") | lookup Device_Details nt_host as host-fqdn output bunit | search bunit="Medicine") | litsearch (index="med" index=nessus sourcetype=nessus:scan | lookup Device_Details nt_host as host-fqdn output bunit | search bunit="Medicine") | fields  keepcolorder=t "*" "_bkt" "_cd" "_si" "host" "index" "linecount" "source" "sourcetype" "splunk_server"  | remotetl  nb=300 et=1660905790.000000 lt=1660906690.000000 remove=true max_count=1000 max_prefetch=100

While the parenthesis balance, I read somewhere they they have to balance within the pipe (|), which they don't. 

We do indeed have a nessus index and several months ago someone started work on getting nessus reporting dashboard in splunk to work (still ongoing). However I am not sure why a simple search on index=Med would reference "nessus". 

Does the litsearch command look wrong?
Where is it picking up the conf to produce such a command and can it be fixed?

I have tried to create a table view of  "med" and I get no entries rather than an error. I did that because it would be good to see the index to know its not a permission error.

 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Perhaps your role has a Search Filter defined that is causing the error.  If so, work with your Splunk admin to fix it.

Yes, parentheses must match within a pipe.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...