<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: changing default-search-timeframes in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/changing-default-search-timeframes/m-p/75261#M4045</link>
    <description>&lt;P&gt;The view is probably configured to be "sticky",  ie up in the &lt;CODE&gt;&amp;lt;view&amp;gt;&lt;/CODE&gt; tag there is no &lt;CODE&gt;isSticky="False"&lt;/CODE&gt; attribute. &lt;/P&gt;

&lt;P&gt;Which means that the view is always watching the TimeRangePicker for changes, and it always remembers the value you last set.  This "sticky" value will always override the default for your user account, whereas another Splunk user who never touched the control, &lt;EM&gt;will&lt;/EM&gt; see your change take effect. &lt;/P&gt;

&lt;P&gt;One clunky thing about stickiness is that if you go now and put &lt;CODE&gt;isSticky="false"&lt;/CODE&gt; into your view, it will indeed no longer record changes to the TimeRangePicker.  Unfortunately it will continue to remember whatever the last change was before you turned stickiness off.    To truly get it to ignore that value you have to go into viewstates.conf manually in &lt;CODE&gt;etc/users/&amp;lt;username&amp;gt;/&amp;lt;appname&amp;gt;/local/viewstates.conf&lt;/CODE&gt; and delete the relevant stanza. &lt;/P&gt;

&lt;P&gt;As a best practice I recommend setting &lt;CODE&gt;isSticky="False"&lt;/CODE&gt; for all advanced XML views, to just avoid this issue entirely.  &lt;/P&gt;</description>
    <pubDate>Sat, 28 Sep 2013 07:28:30 GMT</pubDate>
    <dc:creator>sideview</dc:creator>
    <dc:date>2013-09-28T07:28:30Z</dc:date>
    <item>
      <title>changing default-search-timeframes</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/changing-default-search-timeframes/m-p/75260#M4044</link>
      <description>&lt;P&gt;Hi &lt;/P&gt;

&lt;P&gt;I tried to change the default search times from All time to custom timeframe by changing&lt;/P&gt;

&lt;P&gt;&lt;MODULE name="TimeRangePicker"&gt;&lt;BR /&gt;
    &lt;OBJECT&gt;&lt;PARAM name="selected" /&gt;All time&lt;/OBJECT&gt;&lt;/MODULE&gt;&lt;/P&gt;

&lt;P&gt;&lt;MODULE name="TimeRangePicker"&gt;&lt;BR /&gt;
    &lt;OBJECT&gt;&lt;PARAM name="selected" /&gt;Last 60 minutes&lt;/OBJECT&gt;&lt;/MODULE&gt;&lt;/P&gt;

&lt;P&gt;It's not working .&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2013 13:38:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/changing-default-search-timeframes/m-p/75260#M4044</guid>
      <dc:creator>ajji2684</dc:creator>
      <dc:date>2013-09-27T13:38:56Z</dc:date>
    </item>
    <item>
      <title>Re: changing default-search-timeframes</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/changing-default-search-timeframes/m-p/75261#M4045</link>
      <description>&lt;P&gt;The view is probably configured to be "sticky",  ie up in the &lt;CODE&gt;&amp;lt;view&amp;gt;&lt;/CODE&gt; tag there is no &lt;CODE&gt;isSticky="False"&lt;/CODE&gt; attribute. &lt;/P&gt;

&lt;P&gt;Which means that the view is always watching the TimeRangePicker for changes, and it always remembers the value you last set.  This "sticky" value will always override the default for your user account, whereas another Splunk user who never touched the control, &lt;EM&gt;will&lt;/EM&gt; see your change take effect. &lt;/P&gt;

&lt;P&gt;One clunky thing about stickiness is that if you go now and put &lt;CODE&gt;isSticky="false"&lt;/CODE&gt; into your view, it will indeed no longer record changes to the TimeRangePicker.  Unfortunately it will continue to remember whatever the last change was before you turned stickiness off.    To truly get it to ignore that value you have to go into viewstates.conf manually in &lt;CODE&gt;etc/users/&amp;lt;username&amp;gt;/&amp;lt;appname&amp;gt;/local/viewstates.conf&lt;/CODE&gt; and delete the relevant stanza. &lt;/P&gt;

&lt;P&gt;As a best practice I recommend setting &lt;CODE&gt;isSticky="False"&lt;/CODE&gt; for all advanced XML views, to just avoid this issue entirely.  &lt;/P&gt;</description>
      <pubDate>Sat, 28 Sep 2013 07:28:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/changing-default-search-timeframes/m-p/75261#M4045</guid>
      <dc:creator>sideview</dc:creator>
      <dc:date>2013-09-28T07:28:30Z</dc:date>
    </item>
  </channel>
</rss>

