Reporting

Why am I getting "'savedsearch': Argument "action:email.command" is not supported by this handler" when scheduling a search?

marees123
Path Finder

Please advise what to do if I get the below error when scheduling a search..

Encountered the following error while trying to save: In handler 'savedsearch': Argument "action:email.command" is not supported by this handler
0 Karma

rodrigorsilva
Communicator

I had the same issue, in my case I solved after configure specific capabilities for this role.

edit_search_scheduler

I hope this will help.

Rodrigo Ribeiro

0 Karma

cleavesn
Engager

I saw this yesterday and it was caused by placement of parenthesis around search terms. For ex. index=blah1 source=blah2 ("Term1">=20) ("Term2"="blah3")

Once the parenthesis were removed the search worked properly.

This error message is very confusing and misleading. I have no idea why this would cause the engine to complain about an email action. We hadn't even gotten to the point of trying to create an alert. :-S

As a side note, I do wish that some error messages were more descriptive and offered more guidance on what could be done to remediate the issue. Or perhaps even a link to search for the error term in your default search engine? 🙂

0 Karma

dcarmack_splunk
Splunk Employee
Splunk Employee

I'm going to go out on a limb and bet this is a search that was created a long time ago when your Splunk search head was on a different version than it is today. I bet that is a depreciated option and is no longer supported in your current version, meaning the syntax has changed. If you have access to the file system, open up the savedsearches.conf the search lives in and locate the configuration stanza. The stanza name will simply be the name of the saved search. If that value is present in the stanza, remove and refresh the savedsearches endpoint.

0 Karma

marees123
Path Finder

thanks for your reply.

this is the new search. Got this error when i try to save it.

Also i found that the same search was able to save with another person credential.

Seems like authentication/access issue. Am i correct?

0 Karma

richarddicaire
Path Finder

I'm having same problem. new search, trying to save as alert. Search is:

index=prog cf_app_name="prog-to-syslog"| spath msg | search msg="We have processed 0 event*"

0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...