Dashboards & Visualizations

Dashboard reports not updating since upgrade to Splunk 6

pixelseventy2
Explorer

Hi. I've created a number of dashboards using Saved Searches, instead of inline queries. Since updating to Splunk 6, these aren't updating when the dashboard is refreshed. The panels with inline queries update normally. Do they need to be scheduled to update?

For example, I have a report which shows Administrator logons for the last 6 hours. I want this to update periodically. They are displayed in Chrome with an extension to rotate through the tabs every 60 seconds and refresh.

Should I just schedule these reports to run every 5 minutes or so? Or change them to inline queries.

Thanks.

0 Karma

melting
Splunk Employee
Splunk Employee

Yes, one of the advantages to using saved searches (reports) in dashboards is to have them run faster by using the latest run of that saved search.

So if you want results more frequently you can schedule that search to run more frequently. You could also set the dispatch.ttl to a smaller number so results will expire quicker.

0 Karma

pixelseventy2
Explorer

Unfortunately, I realised that because we're on Splunk Free I can't schedule reports, so I've had to change them all to inline queries.

Has the old "Saved Search" functionality been removed completely in favour of Reports? It was useful to be able to save common queries that I didn't necessarily want as a report, and access them from the menu drop down.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...