Reporting

Dashboard panels showing "In handler 'savedsearch': Error while dispatching search"

shaun_dyble
Explorer

Since upgrading to v6.1.4 some (not all) panels on a certain dashboard show an error "In handler 'savedsearch': Error while dispatching search".

I have found this solution, and changing the search to an inline search does get rid of the error. But Id rather find out the reason why its doing this now.

Has anyone else had panels using saved searches do this?

Thanks

Shaun

iststeam
Engager

In my case, this problem was solved by change the permission setting. I'm not sure does it can apply to your situation.

0 Karma

cafissimo
Communicator

Any news about this issue?

Thanks.

0 Karma

shaun_dyble
Explorer

I have confirmed with Splunk support that defect SPL-81881 has been raised for this and is currently an issue for all versions of 6.1

0 Karma

the_wolverine
Champion

According to known issues SPL-81881 is due to concurrency issues (searches being queued) or real-time search neither which was the case for us because the workaround was simply not to use Simple XML.

"In handler 'savedsearch': Error while dispatching search" may display due to searches being queued or could not run real time due to concurrency limits (SPL-81881)

arichman
Explorer

I am getting this same error when I try to save a report that features a macro in its query.

0 Karma

the_wolverine
Champion

This is occurring with our Simple XML dashboards. A bug is open with Splunk on it and we are waiting on Splunk DEV to figure it out. Try converting to Advanced XML as a workaround. It worked for us.

0 Karma

the_wolverine
Champion

Yes, happening here as well with 6.0.5. Would like to know the reason why.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...