Reporting

loadjob': The savedsearch argument format is invalid. Expecting 'user:application:savedsearch-name'

erickyi
Path Finder

i created a saved report. avgTrafficVolume as admin (saved it as global permission)

Confirmed it is in the reports list
Confirmed it is in the savedSearches.conf

find . -name 'search.conf' -exec grep avgTrafficVolume {} /dev/null \;

./etc/apps/search/local/savedsearches.conf:[avgTrafficVolume]

Run the loadjob command in splunk web
|loadjob savedsearch="admin.search.avgTrafficVolume"

Expected: the saved report is run
Actual: Error in 'SearchOperator:loadjob': The savedsearch argument format is invalid. Expecting 'user:application:savedsearch-name'.

Did I do anything wrong? What do I need to do to get the loadJob to work?

0 Karma
1 Solution

erickyi
Path Finder

Just guessing that loadJob only works with scheduled report; the scheduled report must be run at least once. I have reconfigured the saved report as scheduled. Will check the results tomorrow.

20171101> updated. confirmed it is working.
| loadJob savedsearch="admin:search:avgTrafficVolume"

Sharing the result to all that loadjob works only for scheduled reports. Hope others will find this useful

View solution in original post

0 Karma

ydeveloper
New Member

"Load Job" is not working in production web version 6.4.0.

Kindly suggest.
,i have tried the same but it is still not working.

Kindly help.

0 Karma

erickyi
Path Finder

Just guessing that loadJob only works with scheduled report; the scheduled report must be run at least once. I have reconfigured the saved report as scheduled. Will check the results tomorrow.

20171101> updated. confirmed it is working.
| loadJob savedsearch="admin:search:avgTrafficVolume"

Sharing the result to all that loadjob works only for scheduled reports. Hope others will find this useful

0 Karma

erickyi
Path Finder

i tried this but still failed
| loadjob savedsearch="admin:search:avgTrafficVolume"

Actual: Error in 'SearchOperator:loadjob': Cannot find artifacts for savedsearch_ident 'admin:search:avgTrafficVolume'.

Tried all these combinations
| loadjob savedsearch="avgTrafficVolume"
| loadjob savedsearch="search:avgTrafficVolume"
| loadjob savedsearch="nobody:search:avgTrafficVolume"
| loadjob savedsearch="admin:search:avgTrafficVolume"

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...