Splunk Dev

"Failed to get list of scheduled times…" error when using fill_summary_index.py

andrewdotnich
Explorer

I have some searches that I've scheduled to populate a summary index, but I want to get historical info from them as well so I attempted to backfill the index using the fill_summary_index.py script.

However, when I tried this, I get the following error output:

[root@ bin]# ./splunk cmd python fill_summary_index.py
Please enter the app that contains the search(es): search
Please enter the name of saved search #1 (empty value to stop entering): zzz - DO NOT RUN - DataTable Top Ten Summary Index Search
Please enter the name of saved search #2 (empty value to stop entering): 
Please enter your splunk username: andrewn
Please enter your splunk password: 
Please enter the earliest time (UTC or relative): -6w@w
Please enter the latest time (UTC or relative): -w

*** For saved search 'zzz - DO NOT RUN - DataTable Top Ten Summary Index Search' ***
Failed to get list of scheduled times for saved search 'zzz - DO NOT RUN - DataTable Top Ten Summary Index Search' (app = 'search', error = '[HTTP 404] https://127.0.0.1:8089/servicesNS/nobody/search/saved/searches/zzz%20-%20DO%20NOT%20RUN%20-%20DataTa...; None' 

No searches to run

I've confirmed that the owner of the search is nobody, and I've tried running it with -dedup set and unset, and nothing seems to be working. Why am I getting this error?

Other info:

  • The report is scheduled to run every week, and hasn't run yet - does it have to have already had a scheduled run for the script to work?
  • Digging into the Python script and adding some debug, I see that the Exception that is getting thrown is a splunk.ResourceNotFound Exception - does this help shed some light?
Tags (3)
1 Solution

andrewdotnich
Explorer

I found that the reason I was getting this issue was one of data sync (I think) - I went into my savedsearches.conf and couldn't find the report, even though it was listed (with full search info, mind) in the Manager UI. Deleting and re-inserting the search via the manager resolved the issue and my backfill worked fine…

View solution in original post

the_wolverine
Champion

I encounter this when I forget to "share" my summary search to the search app. I don't have to specifically assign privs to any role but the search app needs access. 2 clicks in UI will fix it.

andrewdotnich
Explorer

I found that the reason I was getting this issue was one of data sync (I think) - I went into my savedsearches.conf and couldn't find the report, even though it was listed (with full search info, mind) in the Manager UI. Deleting and re-inserting the search via the manager resolved the issue and my backfill worked fine…

andrewdotnich
Explorer

that was the main file I was looking in, yes…

0 Karma

hulahoop
Splunk Employee
Splunk Employee

So your saved/scheduled search was not found in any savedsearches.conf, even the one in $SPLUNK_HOME/etc/users/yourusername?

0 Karma

hulahoop
Splunk Employee
Splunk Employee

Hi Andrew, I have seen this error when the -owner flag is not specified. What happens when you add the -owner flag?

andrewdotnich
Explorer

The UI manager claimed that it was both saved and scheduled - I've since discovered the problem, see my answer for info. Thanks for your help, though!

0 Karma

hulahoop
Splunk Employee
Splunk Employee

Have you scheduled the search or is it simply saved?

0 Karma

andrewdotnich
Explorer

Hi hulahoop,

I've tried specifying nobody (what the manager reports as the owner), and I still get the same result 😞

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...