We have just upgraded a splunk instance to 6.0 and the searches which worked previously now display:
In handler 'savedsearch': User
'nobody' could not act as: r4o
The user r4o was the creator of the search, he left some time ago (when we were still on 5.x). The users are handled though a connection to AD (where r4o is not present anymore).
I assume the issue comes from there (?)
Ah, I did figure out how to fix this! In the app that owns the saved search, look for the $app/metadata/local.meta file. In that file, look for the name of the saved search. There is a field called "owner" that has the old AD or LDAP userid in it. Replace that old userid with "nobody" (no quotes). This is a userid that Splunk sets aside to be able to run saved searches when there is no real userid that owns the search anymore.
Restart the search head after the change, or run $SPLUNK/bin/splunk btool fix-dangling and wait a few seconds and reload the dashboard.