Splunk for Active Directory app installed, datas available.
Everything is fine but when I change range date in > Security > User Utilization (sec_user_utilization.xml), graph is modified (from one hour to 4 hours for exemple) but show only one hour data. The problem seem to be with PostProcess and TimeRangePicker modules. This search work well with flashtimeline. Is it normal?
Hey there!It seems i'm facing the same problem as yours and i was wondering if you found a solution to this.I can't find anything related on web or here!
No solution yet. It's in progress with Splunk support.