Reporting

Dashboard panels showing "In handler 'savedsearch': Error while dispatching search"

shaun_dyble
Explorer

Since upgrading to v6.1.4 some (not all) panels on a certain dashboard show an error "In handler 'savedsearch': Error while dispatching search".

I have found this solution, and changing the search to an inline search does get rid of the error. But Id rather find out the reason why its doing this now.

Has anyone else had panels using saved searches do this?

Thanks

Shaun

iststeam
Engager

In my case, this problem was solved by change the permission setting. I'm not sure does it can apply to your situation.

0 Karma

cafissimo
Communicator

Any news about this issue?

Thanks.

0 Karma

shaun_dyble
Explorer

I have confirmed with Splunk support that defect SPL-81881 has been raised for this and is currently an issue for all versions of 6.1

0 Karma

the_wolverine
Champion

According to known issues SPL-81881 is due to concurrency issues (searches being queued) or real-time search neither which was the case for us because the workaround was simply not to use Simple XML.

"In handler 'savedsearch': Error while dispatching search" may display due to searches being queued or could not run real time due to concurrency limits (SPL-81881)

arichman
Explorer

I am getting this same error when I try to save a report that features a macro in its query.

0 Karma

the_wolverine
Champion

This is occurring with our Simple XML dashboards. A bug is open with Splunk on it and we are waiting on Splunk DEV to figure it out. Try converting to Advanced XML as a workaround. It worked for us.

0 Karma

the_wolverine
Champion

Yes, happening here as well with 6.0.5. Would like to know the reason why.

0 Karma
Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...