Splunk Search

Viewstates Error when trying to save/clone/edit search

JDukeSplunk
Builder

So we have a number of searches that cannot be saved or cloned due to viewstate errors. Many of them are accelerated and scheduled and I need to be able to edit them so that they run properly.

alt text

I have checked this answer HERE

I confirmed that my $SPLUNK_HOME/etc/apps/search/metadata/default.meta file has the right entry for viewstates. As shown.
alt text

I have taken some of them and recreated them as new searches, and they saved just fine. Then I can delete them without issue.

What else might I try?

1 Solution

woodcock
Esteemed Legend

Go to the CLI on the Search Head, find the savedsearches.conf file that has the viewstate in it (if *nix, you can use find $SPLUNK_HOME/etc/ -name savedsearches.conf -exec grep -l hqfssli4 {} \;). Stop splunk, edit the file and REMOVE the viewstate line entirely, save it, restart splunk, enjoy. Make a backup of the file first.

View solution in original post

0 Karma

woodcock
Esteemed Legend

Go to the CLI on the Search Head, find the savedsearches.conf file that has the viewstate in it (if *nix, you can use find $SPLUNK_HOME/etc/ -name savedsearches.conf -exec grep -l hqfssli4 {} \;). Stop splunk, edit the file and REMOVE the viewstate line entirely, save it, restart splunk, enjoy. Make a backup of the file first.

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...