Dashboards & Visualizations

Splunk v6.0.4 - Timepicker Preset Missing - "Yesterday"

BP9906
Builder

Hello,
Ever since our upgrade to v6 from v5, the "Yesterday" timepicker preset is missing. I see its not a default option yet it exists in times.conf. Can someone clarify why its missing?

I see this known bug which is perhaps related:
The times.conf spec file still refers to adding submenus in order to customize time range presets; this feature does not exist in Splunk Enterprise 6.x (SPL-76798)

0 Karma

BP9906
Builder

Resolved in v6.0.6

0 Karma

BP9906
Builder

Resolved in v6.0.6

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

I've managed to replicate this - it's related to adding a larger number of custom time range presets. After adding the sixth I see Yesterday disappear, five work fine. You've added eight, so by that logic three should be missing... and indeed, you're missing Yesterday, Year to date, and Week to date - three time ranges off the bottom of the alphabetical order are missing.

This bug is still present in 6.1.1 and not on the list of known issues so please open a support case referencing this answers page.

yannK
Splunk Employee
Splunk Employee

Opened as bug SPL-86219, and added to known issues.
Thanks guys.

martin_mueller
SplunkTrust
SplunkTrust

As a workaround, you should be able to disable a few rarely used time ranges to get Yesterday back.

0 Karma

BP9906
Builder

Splunk v6.0.4

I dont appear to have it, and I see it present in my system/local/times.conf and system/default/times.conf. The first column of "relative" under Presets is the same as the picture in v6.0.4 documentation: http://docs.splunk.com/Documentation/Splunk/6.0.4/SearchTutorial/Aboutthetimerangepicker

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Yesterday should be present in the middle of the second column ("Relative") of the presets section.

The known bug shouldn't be related.

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...