<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Dashboard search mode vs Search in verbose mode in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-mode-vs-Search-in-verbose-mode/m-p/336073#M21769</link>
    <description>&lt;P&gt;Try to change ui-prefs.conf &lt;/P&gt;

&lt;P&gt;[yourappname]&lt;BR /&gt;
display.page.search.mode = verbose&lt;/P&gt;

&lt;P&gt;for e.g.,&lt;/P&gt;

&lt;P&gt;[search] &lt;BR /&gt;
display.page.search.mode = verbose&lt;/P&gt;</description>
    <pubDate>Fri, 28 Jul 2017 03:42:05 GMT</pubDate>
    <dc:creator>sbbadri</dc:creator>
    <dc:date>2017-07-28T03:42:05Z</dc:date>
    <item>
      <title>Splunk Dashboard search mode vs Search in verbose mode</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-mode-vs-Search-in-verbose-mode/m-p/336072#M21768</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have a dashboard that displays results below:&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/3279i28EB7F5753BA1926/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;However, if you open it in search and change search mode to verbose, the result is somehow different:&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/3280i282843371C15AD84/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Now, I'd like to know how do I change the dashboard search mode settings from its default (fast/smart? I'm not sure which.) to verbose via splunk web or via editing any config file. I've read module reference document already but don't know what file to configure or edit. Note that the problem is in the dashboard search mode.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2017 01:47:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-mode-vs-Search-in-verbose-mode/m-p/336072#M21768</guid>
      <dc:creator>lmatilla</dc:creator>
      <dc:date>2017-07-28T01:47:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Dashboard search mode vs Search in verbose mode</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-mode-vs-Search-in-verbose-mode/m-p/336073#M21769</link>
      <description>&lt;P&gt;Try to change ui-prefs.conf &lt;/P&gt;

&lt;P&gt;[yourappname]&lt;BR /&gt;
display.page.search.mode = verbose&lt;/P&gt;

&lt;P&gt;for e.g.,&lt;/P&gt;

&lt;P&gt;[search] &lt;BR /&gt;
display.page.search.mode = verbose&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2017 03:42:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-mode-vs-Search-in-verbose-mode/m-p/336073#M21769</guid>
      <dc:creator>sbbadri</dc:creator>
      <dc:date>2017-07-28T03:42:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Dashboard search mode vs Search in verbose mode</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-mode-vs-Search-in-verbose-mode/m-p/336074#M21770</link>
      <description>&lt;P&gt;Hi! Thank you for your suggestion. When you inspect the job in the dashboard, the saved search properties of the job is now in verbose, however, the result in the dashboard did not change. The result still appear to be in smart mode.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jul 2017 02:18:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-mode-vs-Search-in-verbose-mode/m-p/336074#M21770</guid>
      <dc:creator>lmatilla</dc:creator>
      <dc:date>2017-07-31T02:18:33Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Dashboard search mode vs Search in verbose mode</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-mode-vs-Search-in-verbose-mode/m-p/336075#M21771</link>
      <description>&lt;P&gt;Hi! I guess that the problem is in the query after all. All search modes are displaying the same number of events but different results. This made me re-evaluate my query and edit it. Thanks, guys!&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2017 05:45:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-mode-vs-Search-in-verbose-mode/m-p/336075#M21771</guid>
      <dc:creator>lmatilla</dc:creator>
      <dc:date>2017-08-03T05:45:49Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Dashboard search mode vs Search in verbose mode</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-mode-vs-Search-in-verbose-mode/m-p/336076#M21772</link>
      <description>&lt;P&gt;What was the issue that you found in the query and how did you resolve it? I have a similar issue.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2019 15:18:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-mode-vs-Search-in-verbose-mode/m-p/336076#M21772</guid>
      <dc:creator>zomis</dc:creator>
      <dc:date>2019-12-10T15:18:31Z</dc:date>
    </item>
  </channel>
</rss>

