Reporting

Cannot find artifacts for savedsearch_ident...

dm1
Contributor

There is a dashboard which uses a scheduled search using the |loadjob command. 

I recently changed the search query for that scheduled search, which was basically added a index = indexname stanza to it to make it a little more efficient. 

However, after doing that, the dashboard started showing the below error

Cannot find artifacts for savedsearch_ident...

When I click on the "View Recent" option of the saved search, it still loads the results.

Any ideas? 

Labels (2)
Tags (1)
0 Karma
1 Solution

dm1
Contributor

I had a look through those posts but unfortunately, scenarios mentioned in those were not relevant to me.

To figure out the cause of this issue, I created a test scheduled search (SS) with almost same configuration (sourcetype=sample | stats count) as the one in question and ran it on a smaller schedule.

After the 1st run of SS,  loadjob command worked.

Before the 2nd SS run, I changed the search query to add the index= stanza. This time I again manually ran the loadjob command and it gave the same error as I got above. That confirmed in my case the error was more due to the fact that I changed the search query. After 2nd scheduled run (after query modification was made), loadjob command worked perfectly.

View solution in original post

0 Karma

dm1
Contributor

I had a look through those posts but unfortunately, scenarios mentioned in those were not relevant to me.

To figure out the cause of this issue, I created a test scheduled search (SS) with almost same configuration (sourcetype=sample | stats count) as the one in question and ran it on a smaller schedule.

After the 1st run of SS,  loadjob command worked.

Before the 2nd SS run, I changed the search query to add the index= stanza. This time I again manually ran the loadjob command and it gave the same error as I got above. That confirmed in my case the error was more due to the fact that I changed the search query. After 2nd scheduled run (after query modification was made), loadjob command worked perfectly.

0 Karma
Get Updates on the Splunk Community!

This Week's Community Digest - Splunk Community Happenings [9.26.22]

Get the latest news and updates from the Splunk Community here! Upcoming User Group Events! 👏 Check ...

BSides Splunk 2022 - The Call for Papers is now Open!

TLDR; Main Site: https://bsidessplunk.com CFP Site: https://bsidessplunk.com/cfp CFP Opens: December 15th, ...

Sending Metrics to Splunk Enterprise With the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...