Reporting

Why am I getting "'savedsearch': Argument "action:email.command" is not supported by this handler" when scheduling a search?

marees123
Path Finder

Please advise what to do if I get the below error when scheduling a search..

Encountered the following error while trying to save: In handler 'savedsearch': Argument "action:email.command" is not supported by this handler
0 Karma

rodrigorsilva
Communicator

I had the same issue, in my case I solved after configure specific capabilities for this role.

edit_search_scheduler

I hope this will help.

Rodrigo Ribeiro

0 Karma

cleavesn
Engager

I saw this yesterday and it was caused by placement of parenthesis around search terms. For ex. index=blah1 source=blah2 ("Term1">=20) ("Term2"="blah3")

Once the parenthesis were removed the search worked properly.

This error message is very confusing and misleading. I have no idea why this would cause the engine to complain about an email action. We hadn't even gotten to the point of trying to create an alert. :-S

As a side note, I do wish that some error messages were more descriptive and offered more guidance on what could be done to remediate the issue. Or perhaps even a link to search for the error term in your default search engine? 🙂

0 Karma

dcarmack_splunk
Splunk Employee
Splunk Employee

I'm going to go out on a limb and bet this is a search that was created a long time ago when your Splunk search head was on a different version than it is today. I bet that is a depreciated option and is no longer supported in your current version, meaning the syntax has changed. If you have access to the file system, open up the savedsearches.conf the search lives in and locate the configuration stanza. The stanza name will simply be the name of the saved search. If that value is present in the stanza, remove and refresh the savedsearches endpoint.

0 Karma

marees123
Path Finder

thanks for your reply.

this is the new search. Got this error when i try to save it.

Also i found that the same search was able to save with another person credential.

Seems like authentication/access issue. Am i correct?

0 Karma

richarddicaire
Path Finder

I'm having same problem. new search, trying to save as alert. Search is:

index=prog cf_app_name="prog-to-syslog"| spath msg | search msg="We have processed 0 event*"

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...