Dashboards & Visualizations

How to change default time range in the pivot window?

Explorer

I'd like to change the the default time range in the pivot window from "All time" to "Last 24 hours" for instance. The reason is I'm working with a very large deployment and pivoting on a large data model is something we try not to do. I realized that there has been a question posted 2 years ago (2014) and the answer was this feature would be available in future release. Have we had it yet?

Thanks.

Influencer

Try this

[general_default]
default_namespace = launcher
appOrder = search
default_earliest_time = -48h
default_latest_time = now
0 Karma

Champion

Does not work for me. I put that stanza in <SPLUNK_ROOT>/etc/system/local/user-prefs.conf on Splunk 7.0.2, and still get All Time as the default search time for Pivot page.

0 Karma

Influencer

It works for us. For us in our pivot interface the default is -48h
We are using Splunk 6.4.5

0 Karma

Champion

I am not sure what you are seeing or where you are putting your conig settings because I am not seeing what you see.

First, let's define working. In your version of splunk, what time range do you get by default when you are on the Pivot creation screen that has the url path app/launcher/pivot? This is the page the original question is referring to where it always seems to default to "All Time".

Now, I just took your config settings and put them in user-prefs.conf under <SPLUNK_ROOT>/etc/system/local/ and in <SPLUNK_ROOT>/etc/users/admin/user-prefs/local on 6.4, 6.5, and 7.0 and there was no effect on the default search period of the Pivot creation page.

In all cases I made the config changes, and then rebooted Splunk. No change to the Pivot creation page was observed.

0 Karma

Champion

If anything, you would think that Splunk would apply the settings in ui-prefs.conf to the pivot page just like Splunk does to other pages, at least when you are in the context of an app.

Right now, neither the pivot page nor the dataset page follow the global default settings or specific stanza settings for dispatch times. For example, in Splunk 7.0 the following settings have no effect on the pivot and dataset pages: pivot uses the default All Time and dataset uses Past 24 hours.

# ui-prefs.conf in custom app

[default]
dispatch.earliest_time = @w1
dispatch.latest_time   = now

[pivot]
dispatch.earliest_time = @w1
dispatch.latest_time   = now

[dataset]
dispatch.earliest_time = @w1
dispatch.latest_time   = now
0 Karma

Champion

Hi thenhaque,
The another way to do this you can use "Dataset" feature by changing search preference setting to apply default time range as last 24 hours. And then visualise dataset using pivots.

0 Karma

Champion

Can you try something:

 []
 dispatch.earliest_time = @w1
 dispatch.latest_time   = now
0 Karma

Champion

No, it doesn't appear to work.

I am sorry but I am going to downvote the next answer that appears to be untested by the poster. These config changes are easily tested by the people suggesting them. Please save me the trouble of testing it or show proof that your suggestion does work for you and I must be doing something wrong.

0 Karma