Reporting

Saved search (report) not working on dashboard panel with pipeline:scheduler disabled

caseypike
Path Finder

To reduce resource burden of scheduled searches (reports) and alerts off of the search heads, I have configured a default-mode.conf file to disable the pipeline:scheduler and created a separate job server. In Splunk v5, when I added a panel calling a saved search to a simple dashboard, it ran with no issues even though the pipeline:scheduler was disabled. Upgrading to Splunk v6, I now get “In handler ‘savedsearch’: Search scheduler has not started yet.” as an error in that panel.

Cloning to an inline search works. Also, converting the panel to run an inline search which calls the report using the ‘savedsearch’ command works.

Does running a saved search (report) in a dashboard panel on an ad-hoc basis (every time the dashboard is loaded) not work anymore in v6 with the scheduler disabled?

1 Solution

melting
Splunk Employee
Splunk Employee

You are correct. In Splunk 6.0 saved searches are dispatched via the saved search endpoint, which requires the scheduler to be enabled.

View solution in original post

melting
Splunk Employee
Splunk Employee

You are correct. In Splunk 6.0 saved searches are dispatched via the saved search endpoint, which requires the scheduler to be enabled.

robsuh
Explorer

dshpritz What do you mean by SH?

Nevermind, I think it means Search Head.

0 Karma

dshpritz
SplunkTrust
SplunkTrust

FYI for others:
Bug in Splunk 6 (SPL-74761) means that disabling scheduled searches on a SH will result in that SH being unable to retrieve saved search results. Dashboards could fail if using saved search results, links to results from emails would fail.

caseypike
Path Finder

Not the answer I wanted... 🙂 Thanks for responding so quickly though.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...