Dashboards & Visualizations

Splunk Dashboard search mode vs Search in verbose mode

lmatilla
Explorer

Hi,

I have a dashboard that displays results below:

alt text

However, if you open it in search and change search mode to verbose, the result is somehow different:

alt text

Now, I'd like to know how do I change the dashboard search mode settings from its default (fast/smart? I'm not sure which.) to verbose via splunk web or via editing any config file. I've read module reference document already but don't know what file to configure or edit. Note that the problem is in the dashboard search mode.

0 Karma

lmatilla
Explorer

Hi! I guess that the problem is in the query after all. All search modes are displaying the same number of events but different results. This made me re-evaluate my query and edit it. Thanks, guys!

0 Karma

zomis
Explorer

What was the issue that you found in the query and how did you resolve it? I have a similar issue.

0 Karma

sbbadri
Motivator

Try to change ui-prefs.conf

[yourappname]
display.page.search.mode = verbose

for e.g.,

[search]
display.page.search.mode = verbose

0 Karma

lmatilla
Explorer

Hi! Thank you for your suggestion. When you inspect the job in the dashboard, the saved search properties of the job is now in verbose, however, the result in the dashboard did not change. The result still appear to be in smart mode.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...