Security

Error in 'SearchParser': Missing a search command before ' '.

alenseb
Communicator

Hi,

I am trying to access one of my saved Searches, but this error is shown all of a sudden.
My syntax is correct as the same code was working sometime back.
Is this a product bug?

Please help.

Thanks!!

0 Karma

ryonts
Explorer

I discovered today that after modifying a saved search to format it for better readability, this error showed up. The problem was that in formatting it, I added some CRLF characters. Afterwards, the error showed up. For some reason, CRLF are NOT ignored, but affect the search string. Hopefully this can help your situation. (I HATE unformatted search strings, too difficult to read when all jumbled up!)

0 Karma

ryonts
Explorer

I discovered today that after modifying a saved search to format it for better readability, this error showed up. The problem was that in formatting it, I added some CRLF characters. Afterwards, the error showed up. For some reason, CRLF are NOT ignored, but affect the search string. Hopefully this can help your situation. (I HATE unformatted search strings, too difficult to read when all jumbled up!)

MarioM
Motivator

to get help you need to give more infos:
-post the complete search
-splunk version
-permissions of the searches/report/dashboards/apps...

0 Karma

alenseb
Communicator

Just read somewhere for these of errors, you have to re-install.
Any idea on why?

0 Karma

alenseb
Communicator

i haven't changed anything.

0 Karma

MuS
SplunkTrust
SplunkTrust

so what did change since it last was working?

0 Karma

alenseb
Communicator

The search works just fine, but when i search as a | savedsearch i get the error.

Also the same SavedSearch command was working fine sometime back.

0 Karma

lguinn2
Legend

We need to see the actual search text. Go to the Manager and edit the saved search. Copy the search into a comment.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...