i am also getting the same error while creating a correlation search. Infact i get the same error when i try to create an alert in Splunk enterprise suite.
I think it's because of some sort of issue with the Scheduler. Just thinking out loud.
@lakshman239 I am running Splunk 7.2.1 with ES 5.2
ok, I am on 7.0.3 with ES 5.1.1 still and don't see any issue. This comes from schedule_priority setting in the savedsearches.conf . Could you try the following?
This could indicate any issues with permissions/roles/capabilities to user.