Dashboards & Visualizations

What is the date display difference between Dashboard Studio and Classic Dashboard?

Tainted_Rajaion
Explorer

Hello community,

I'm trying to make a simple dashboard but I'm running into a problem with displaying dates. I'm using Splunk Enterprise version 8.2.3.
In the data that I have to work, I made changes in my search to display the time in the correct time zone directly (+2 hour). My research looks like this (it is certainly perfectible but the subject is not there):

Tainted_Rajaion_0-1662631432037.png

 

Having obtained what I wanted in terms of display, I prepared a dashboard but when I do it with Dashboard Studio, the display of dates does not seem to take some of my modifications:

Tainted_Rajaion_1-1662631432349.png

 

However, by making the same request in a classic Dashboard, I no longer have the problem:

Tainted_Rajaion_2-1662631431801.png

 

 

Is there something specific to do for Dashboard Studio? Am I the only one having the problem?

Best regards,

Tainted Rajaion

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Fair enough - moderators (such as myself) can move messages if we notice that they are in the wrong place

In answer to your question, it does appear to be an issue with Dashboard Studio even in 9.0.1

You could try adding a trailing space to your format string so Splunk make the assumption that it is a timestamp

View solution in original post

Tainted_Rajaion
Explorer

I would remember that to avoid this kind of topic move.

Regarding my problem, space seems to work but not everywhere. I'll dig around there and I'll come back to give you my results.

Best regards,

Tainted Rajaion

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please don't keep deleting messages and reposting exactly the same message - with a little patience, you may find your message gets answered eventually.

0 Karma

Tainted_Rajaion
Explorer

Hello @ITWhisperer 

There is no problem with patience, I had just noticed after my publication that I was not in the right room, and having not found how to move it, I just deleted the old one to put it back the same but in the right living room.

Best regards,

Tainted Rajaion

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Fair enough - moderators (such as myself) can move messages if we notice that they are in the wrong place

In answer to your question, it does appear to be an issue with Dashboard Studio even in 9.0.1

You could try adding a trailing space to your format string so Splunk make the assumption that it is a timestamp

Tainted_Rajaion
Explorer

The space works well! It's subtle as a trick, I keep it warm, thank you very much for your help!

Tainted_Rajaion_0-1662638056646.png

 

Best regards,

Tainted Rajaion

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...