Last time I started to get a notification "Unable to get viewstate information; formatting may not be correct" at the top of Splunk screen. I have a lot of searches and dashboards, because all employees can create their own stuff. I need to find what cause that notification and resolve it.
Does anyone have idea how to "debug" this?
Unfortunately this isn't very helpful. I get warning "Unable to get viewstate information; formatting may not be correct" without any name of search or dashboard. I have found file savedsearch.conf in app Search, but there are hundreds of searches. Removing vsids from all search isn't good idea.