All Apps and Add-ons

PostProcess show one hour data on Splunk for Active Directory app

bruno_marchetti
Engager

Splunk for Active Directory app installed, datas available.
Everything is fine but when I change range date in > Security > User Utilization (sec_user_utilization.xml), graph is modified (from one hour to 4 hours for exemple) but show only one hour data. The problem seem to be with PostProcess and TimeRangePicker modules. This search work well with flashtimeline. Is it normal?

synodineios
Explorer

Hey there!It seems i'm facing the same problem as yours and i was wondering if you found a solution to this.I can't find anything related on web or here!

0 Karma

bruno_marchetti
Engager

No solution yet. It's in progress with Splunk support.

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...