Reporting

Dashboard panels showing "In handler 'savedsearch': Error while dispatching search"

shaun_dyble
Explorer

Since upgrading to v6.1.4 some (not all) panels on a certain dashboard show an error "In handler 'savedsearch': Error while dispatching search".

I have found this solution, and changing the search to an inline search does get rid of the error. But Id rather find out the reason why its doing this now.

Has anyone else had panels using saved searches do this?

Thanks

Shaun

iststeam
Engager

In my case, this problem was solved by change the permission setting. I'm not sure does it can apply to your situation.

0 Karma

cafissimo
Communicator

Any news about this issue?

Thanks.

0 Karma

shaun_dyble
Explorer

I have confirmed with Splunk support that defect SPL-81881 has been raised for this and is currently an issue for all versions of 6.1

0 Karma

the_wolverine
Champion

According to known issues SPL-81881 is due to concurrency issues (searches being queued) or real-time search neither which was the case for us because the workaround was simply not to use Simple XML.

"In handler 'savedsearch': Error while dispatching search" may display due to searches being queued or could not run real time due to concurrency limits (SPL-81881)

arichman
Explorer

I am getting this same error when I try to save a report that features a macro in its query.

0 Karma

the_wolverine
Champion

This is occurring with our Simple XML dashboards. A bug is open with Splunk on it and we are waiting on Splunk DEV to figure it out. Try converting to Advanced XML as a workaround. It worked for us.

0 Karma

the_wolverine
Champion

Yes, happening here as well with 6.0.5. Would like to know the reason why.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...