are you sure the user has access to the indexes or can you view the search run which converts the tokens to values and copy/paste that in another splunk search running as your custom user?
... View more
@niketn - I confirmed this does work as you described while testing in 6.5, whoever reset_after does not seem to work in 6.3. After reviewing the documentation, "reset_after" was introduced in 6.4.
... View more
I had a similar issue with the same error message and found it to be related to the length of the postprocess search. You can test by moving more of the search into the base search or creating a macro to hold the postprocess search contents. Good luck.
... View more