Dashboards & Visualizations

In handler 'saved search': Error while dispatching search

yinzs02
Engager

I have a dashboard which include 8 panels. Each panel has a saved search attached to it. Everything worked fine till this morning.

When I load the dashboard, I see a few of those panels loaded fine, but a few others gave this "In handler saved search: Error while dispatching search" alert. I cleared everything under the dispatch directory, but it didn't help.

I googled it, and looks like another user ran into the same issue, and he/she fixed it with the option "Clone to an inline search". It's not necessarily what I wish to do though.

Does anyone know if it's a bug with version 6.1? I upgraded my Splunk from 5 to 6.1 a few weeks ago, and this problem only appeared today.

Thanks for any comments or suggestions.

jkat54
SplunkTrust
SplunkTrust

My guess is that you're running into a max searches limit issue and that your user role isnt allowed to have as many searches running as you' have.

You can open the panel in search, and then use the job inspector to figure out more details related to why the search is failing.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Take a look at the _internal index at the time of the error message for any clues.

0 Karma

the_wolverine
Champion

We are seeing lots of issues like this with our Simple XML dashboards in version 6.0x. Splunk is investigating. They tell us that we need to convert dashboards to HTML as a workaround but we have found that converting to Advanced XML has worked for us -- FYI, Splunk advises against using Advanced XML.

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...