Monitoring Splunk

How do I fix: 'litsearch' command: Unable to parse the search: unbalanced parentheses?

Mr_Johnson42
Observer

I'm an end user! It appears to be just my user account. we dont seem to be able to find the answer

When I do any search (such as index="med") I get 
"Error in 'litsearch' command: Unable to parse the search: unbalanced parentheses."

When I go through the logs I was surprised to see that such a simple search resulted in

litsearch (index="med" index=nessus ((source="SI - EZproxy" orig_sourcetype="nessus:scan") OR sourcetype="nessus:scan") | lookup Device_Details nt_host as host-fqdn output bunit | search bunit="Medicine") | litsearch (index="med" index=nessus sourcetype=nessus:scan | lookup Device_Details nt_host as host-fqdn output bunit | search bunit="Medicine") | fields  keepcolorder=t "*" "_bkt" "_cd" "_si" "host" "index" "linecount" "source" "sourcetype" "splunk_server"  | remotetl  nb=300 et=1660905790.000000 lt=1660906690.000000 remove=true max_count=1000 max_prefetch=100

While the parenthesis balance, I read somewhere they they have to balance within the pipe (|), which they don't. 

We do indeed have a nessus index and several months ago someone started work on getting nessus reporting dashboard in splunk to work (still ongoing). However I am not sure why a simple search on index=Med would reference "nessus". 

Does the litsearch command look wrong?
Where is it picking up the conf to produce such a command and can it be fixed?

I have tried to create a table view of  "med" and I get no entries rather than an error. I did that because it would be good to see the index to know its not a permission error.

 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Perhaps your role has a Search Filter defined that is causing the error.  If so, work with your Splunk admin to fix it.

Yes, parentheses must match within a pipe.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...