Hi guys, I have an issue with a saved (and scheduled) search with no result. If I schedule a search that returns no results and I try to get it with the command
| laodjob savedsearch="admin:app:label"
Splunk returns following error:
Encountered an error while reading file '$splunk_home$/var/run/splunk/dispatch/ .... /results.csv.gz'.
If I try to change the time window where the search works (to "force" it to find some results), it works great.
How can I be sure that Splunk creates the .cvs.gz file in any case even if the search does find no results? I can not dispatch a dashboard that returns a bad error like this!
thanks :)