Security

500 Internal Server "TypeError: 'NoneType' object is unsubscriptable" Error

mallem
Path Finder

I pushed a group of saved searches to a newly built v4.1.4 indexer from a v4.1.4 deployment head. The .bundle files end up in the /opt/splunk/var/run/[servername] directory on the target indexer and seem to be running fine on their 2-minute schedules. The problem I have is when I go to Manager --> Searches and Reports, and click on the "Run" link located to the far right of the saved searches. When clicking that link, I get the 500 Internal Server Error TypeError: 'NoneType' object is unsubscriptable message. Scoured Splunk.com for any info on what app.conf changes can be made, but came up with nothing.

0 Karma

mallem
Path Finder

There's no "debugging info" link. Below is the contents of everything on the screen at the time of the error.

500 Internal Server Error TypeError: 'NoneType' object is unsubscriptable

This page was linked to from https://splunkserver3.webum.net/en-US/manager/search/saved/searches.

You are using splunkserver3.webum.net, which is connected to splunkd @82143 at https://127.0.0.1:8089 on Mon Nov 29 08:38:36 2010.

0 Karma

sideview
SplunkTrust
SplunkTrust

There should be a 'debugging info' link or something on that 500 page. Or failing that a stack trace which should show up in the web_service log in index=_internal. Can you paste in the info from either of those?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

    Thursday, June 25, 2026  |  11AM PDT / 2PM EDT  Duration: 1 Hour (Includes live Q&A) Register to ...

Analytics Workspace deprecation

As of Splunk Cloud Platform 10.4.2604 and Splunk Enterprise 10.4, Analytics Workspace is now deprecated. ...

Splunk Developer Day Recap: Building, Publishing, and Growing on the Splunk Platform

Splunk Developer Day brought the Splunk developer community together for a practical look at what it means to ...