Hello,
When trying to execute a savedsearch from the UI , it throws an error :Error in 'savedsearch' command: Encountered the following error while building a search for saved search 'Incident Review - Main': Error while replacing variable name='type_filter'. Could not find variable in the argument map..
There is no variable by this name - type_filter in the query.
We are on the latest version of Splunk cloud 8.2.x. This search was working fine till yesterday and nothing has changed from our end. The Splunk cloud team did perform a maintenance for updates last night.
How to resolve this ? Any assistance appreciate.
similar error here, resolved
i had a correlation rule is ES calling saved search, it required the addition of "type_filter"
| savedsearch "Incident Review - Main" time_filter="" event_id_filter="" source_filter="" security_domain_filter="" status_filter="status=\"1\"" owner_filter="" urgency_filter="urgency=\"critical\" OR urgency=\"high\" OR urgency=\"medium\" OR urgency=\"low\" OR urgency=\"unknown\"" tag_filter=""
Did you get any solution for this issue ?
No not yet