Splunk Search

MPLS_login_102_1 error message

alextsui
Path Finder

Hi. Some of the scheduled saved searches have stopped running. When click on these saved searches from Search App's "Searches & Reports" Navigation dropdown menu, the searches run fine. But when click on the "run" link of these saved searches from Manager > Searches and Reports, an error occurred on the web page like the screenshot display below:

alt text

If the screenshot picture does not display, the actual error message is listed below: "The following requested saved search is unknown""MPLS_login_102_1".As a result, Splunk is unable to redirect to a view."

Any suggestions to correct the problem?

Thanks.

Tags (1)
0 Karma

Genti
Splunk Employee
Splunk Employee

Check if the saved search is actually there. Look for and find all your savedsearches.conf files within your splunk/
Here are a couple of locations
./etc/apps/search/local/savedsearches.conf
./etc/system/default/savedsearches.conf
./etc/users/admin/search/local/savedsearches.conf

and then check your splunk/var/run/splunk/dispatch directory and see if a savedsearch with the above name is scheduled to run. If there is no saved search but still the search is scheduled, delete the scheduled search (rmdir) and you should not be seeing those errors.
If the saved search exists but you still see that error, send your diag to support and they should be able to troubleshoot this issue..

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

It is also possible that the searches are marked "not visible" or that they are private to only one specific user, or not readable to a user in your role.

0 Karma
Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...