Reporting

Why am I getting "Error in 'savedsearch' command: Unable to find saved search named..."?

ben_leung
Builder

splunkd.log

09-23-2014 19:17:05.101 +0000 ERROR SearchOperator:savedsplunk - Error in 'savedsearch' command: Unable to find saved search named 'ADSCV_SSP_REQUESTS'.

Running the command

| savedsearch ADSCV_SSP_REQUESTS

Gives me a UI error

Error in 'savedsearch' command: Unable to find saved search named 'ADSCV_SSP_REQUESTS'.

The saved search is scheduled under the same user trying to run the saved search command. The saved search has read access to all roles. The saved search is shared at the app level in the search app. What is causing this error?

Tags (2)
1 Solution

drrushi_splunk
Splunk Employee
Splunk Employee

Ben - can you ensure that the savedsearch in question is not Disabled? This would cause the above error.

View solution in original post

rupadantuluri1
New Member

i am facing error when running : hostname:port/services/search/jobs/export end point through postman

Input : search%3D%7C%20savedsearch%20MySavedSearch

Output :

<messages>
    <msg type="FATAL">Empty search.</msg>
</messages>

Same saved search is running in web successfully.

0 Karma

drrushi_splunk
Splunk Employee
Splunk Employee

Ben - can you ensure that the savedsearch in question is not Disabled? This would cause the above error.

ben_leung
Builder

Turns out that the search was disabled due to type. Had a default stanza in between a saved search, causing all of the underlying searches that was owned by the user to be disabled.

ben_leung
Builder

The saved search is shared at the app level, with read access to all roles. Other roles can run the | savedsearch command without getting the error.

ben_leung
Builder

I have ran the saved search command using an admin role user and was successful. I created a new account with the same role as the user that owns this search and has it scheduled. It also ran successful. Running it as the owner seems to be causing the error.

Please let me know how I can get this resolved.

Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...