Dashboards & Visualizations

Splunk v6.0.4 - Timepicker Preset Missing - "Yesterday"

BP9906
Builder

Hello,
Ever since our upgrade to v6 from v5, the "Yesterday" timepicker preset is missing. I see its not a default option yet it exists in times.conf. Can someone clarify why its missing?

I see this known bug which is perhaps related:
The times.conf spec file still refers to adding submenus in order to customize time range presets; this feature does not exist in Splunk Enterprise 6.x (SPL-76798)

0 Karma

BP9906
Builder

Resolved in v6.0.6

0 Karma

BP9906
Builder

Resolved in v6.0.6

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

I've managed to replicate this - it's related to adding a larger number of custom time range presets. After adding the sixth I see Yesterday disappear, five work fine. You've added eight, so by that logic three should be missing... and indeed, you're missing Yesterday, Year to date, and Week to date - three time ranges off the bottom of the alphabetical order are missing.

This bug is still present in 6.1.1 and not on the list of known issues so please open a support case referencing this answers page.

yannK
Splunk Employee
Splunk Employee

Opened as bug SPL-86219, and added to known issues.
Thanks guys.

martin_mueller
SplunkTrust
SplunkTrust

As a workaround, you should be able to disable a few rarely used time ranges to get Yesterday back.

0 Karma

BP9906
Builder

Splunk v6.0.4

I dont appear to have it, and I see it present in my system/local/times.conf and system/default/times.conf. The first column of "relative" under Presets is the same as the picture in v6.0.4 documentation: http://docs.splunk.com/Documentation/Splunk/6.0.4/SearchTutorial/Aboutthetimerangepicker

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Yesterday should be present in the middle of the second column ("Relative") of the presets section.

The known bug shouldn't be related.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...