Reporting

Dashboard panels showing "In handler 'savedsearch': Error while dispatching search"

shaun_dyble
Explorer

Since upgrading to v6.1.4 some (not all) panels on a certain dashboard show an error "In handler 'savedsearch': Error while dispatching search".

I have found this solution, and changing the search to an inline search does get rid of the error. But Id rather find out the reason why its doing this now.

Has anyone else had panels using saved searches do this?

Thanks

Shaun

iststeam
Engager

In my case, this problem was solved by change the permission setting. I'm not sure does it can apply to your situation.

0 Karma

cafissimo
Communicator

Any news about this issue?

Thanks.

0 Karma

shaun_dyble
Explorer

I have confirmed with Splunk support that defect SPL-81881 has been raised for this and is currently an issue for all versions of 6.1

0 Karma

the_wolverine
Champion

According to known issues SPL-81881 is due to concurrency issues (searches being queued) or real-time search neither which was the case for us because the workaround was simply not to use Simple XML.

"In handler 'savedsearch': Error while dispatching search" may display due to searches being queued or could not run real time due to concurrency limits (SPL-81881)

arichman
Explorer

I am getting this same error when I try to save a report that features a macro in its query.

0 Karma

the_wolverine
Champion

This is occurring with our Simple XML dashboards. A bug is open with Splunk on it and we are waiting on Splunk DEV to figure it out. Try converting to Advanced XML as a workaround. It worked for us.

0 Karma

the_wolverine
Champion

Yes, happening here as well with 6.0.5. Would like to know the reason why.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...