<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Saved Searches from Before Splunk 6 Upgrade Display Differently in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/Saved-Searches-from-Before-Splunk-6-Upgrade-Display-Differently/m-p/140245#M3136</link>
    <description>&lt;P&gt;install a test instance of Splunk 6 on some spare system or VM. Then manually create the saved searches on that system and ingest just enough data to get at least a couple events (or more) in it for testing. See if you fix the problem. If so, you can be sure it's a localized issue on your prod system. I'd look for anything in */local directories, especially about viewstates.conf, ui-prefs.conf, and event_renderers.conf. There may be others, too...&lt;/P&gt;</description>
    <pubDate>Thu, 14 Nov 2013 01:14:38 GMT</pubDate>
    <dc:creator>jtrucks</dc:creator>
    <dc:date>2013-11-14T01:14:38Z</dc:date>
    <item>
      <title>Saved Searches from Before Splunk 6 Upgrade Display Differently</title>
      <link>https://community.splunk.com/t5/Reporting/Saved-Searches-from-Before-Splunk-6-Upgrade-Display-Differently/m-p/140243#M3134</link>
      <description>&lt;P&gt;I noticed that after the Splunk 6 Upgrade, all of the saved searches displayed in what I called a "hybrid" format, where the new Splunk 6 feel exists on the upper part of the page, but starting at the search bar, it looks like Splunk 5.  I think this might be due to older viewstates or possibly something in the savedsearches.conf.  I have tried a few things but nothing seems to convert it fully to Splunk 6 look and feel.&lt;/P&gt;

&lt;P&gt;Any suggestions would be appreciated.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2013 14:48:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Saved-Searches-from-Before-Splunk-6-Upgrade-Display-Differently/m-p/140243#M3134</guid>
      <dc:creator>jodros</dc:creator>
      <dc:date>2013-11-13T14:48:28Z</dc:date>
    </item>
    <item>
      <title>Re: Saved Searches from Before Splunk 6 Upgrade Display Differently</title>
      <link>https://community.splunk.com/t5/Reporting/Saved-Searches-from-Before-Splunk-6-Upgrade-Display-Differently/m-p/140244#M3135</link>
      <description>&lt;P&gt;Afternoon bump.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2013 22:33:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Saved-Searches-from-Before-Splunk-6-Upgrade-Display-Differently/m-p/140244#M3135</guid>
      <dc:creator>jodros</dc:creator>
      <dc:date>2013-11-13T22:33:22Z</dc:date>
    </item>
    <item>
      <title>Re: Saved Searches from Before Splunk 6 Upgrade Display Differently</title>
      <link>https://community.splunk.com/t5/Reporting/Saved-Searches-from-Before-Splunk-6-Upgrade-Display-Differently/m-p/140245#M3136</link>
      <description>&lt;P&gt;install a test instance of Splunk 6 on some spare system or VM. Then manually create the saved searches on that system and ingest just enough data to get at least a couple events (or more) in it for testing. See if you fix the problem. If so, you can be sure it's a localized issue on your prod system. I'd look for anything in */local directories, especially about viewstates.conf, ui-prefs.conf, and event_renderers.conf. There may be others, too...&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2013 01:14:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Saved-Searches-from-Before-Splunk-6-Upgrade-Display-Differently/m-p/140245#M3136</guid>
      <dc:creator>jtrucks</dc:creator>
      <dc:date>2013-11-14T01:14:38Z</dc:date>
    </item>
    <item>
      <title>Re: Saved Searches from Before Splunk 6 Upgrade Display Differently</title>
      <link>https://community.splunk.com/t5/Reporting/Saved-Searches-from-Before-Splunk-6-Upgrade-Display-Differently/m-p/140246#M3137</link>
      <description>&lt;P&gt;I had to comment out the following lines in savedsearches.conf for my searches to display in the new Splunk 6 format:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;#displayview = flashtimeline
#request.ui_dispatch_view = flashtimeline
#vsid = &amp;lt;some unique value&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;After commenting out the vsid line, it auto gens a new one in both of the savedsearches.conf and viewstates.conf.  I was not able to get the saved searches to display properly without commenting out all three of these lines.  I originally thought just the vsid was the only thing that was needed, but it turns out they were all needed.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2013 16:22:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Saved-Searches-from-Before-Splunk-6-Upgrade-Display-Differently/m-p/140246#M3137</guid>
      <dc:creator>jodros</dc:creator>
      <dc:date>2013-11-22T16:22:20Z</dc:date>
    </item>
  </channel>
</rss>

