Dashboards & Visualizations

What is the date display difference between Dashboard Studio and Classic Dashboard?

Tainted_Rajaion
Explorer

Hello community,

I'm trying to make a simple dashboard but I'm running into a problem with displaying dates. I'm using Splunk Enterprise version 8.2.3.
In the data that I have to work, I made changes in my search to display the time in the correct time zone directly (+2 hour). My research looks like this (it is certainly perfectible but the subject is not there):

Tainted_Rajaion_0-1662631432037.png

 

Having obtained what I wanted in terms of display, I prepared a dashboard but when I do it with Dashboard Studio, the display of dates does not seem to take some of my modifications:

Tainted_Rajaion_1-1662631432349.png

 

However, by making the same request in a classic Dashboard, I no longer have the problem:

Tainted_Rajaion_2-1662631431801.png

 

 

Is there something specific to do for Dashboard Studio? Am I the only one having the problem?

Best regards,

Tainted Rajaion

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Fair enough - moderators (such as myself) can move messages if we notice that they are in the wrong place

In answer to your question, it does appear to be an issue with Dashboard Studio even in 9.0.1

You could try adding a trailing space to your format string so Splunk make the assumption that it is a timestamp

View solution in original post

Tainted_Rajaion
Explorer

I would remember that to avoid this kind of topic move.

Regarding my problem, space seems to work but not everywhere. I'll dig around there and I'll come back to give you my results.

Best regards,

Tainted Rajaion

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please don't keep deleting messages and reposting exactly the same message - with a little patience, you may find your message gets answered eventually.

0 Karma

Tainted_Rajaion
Explorer

Hello @ITWhisperer 

There is no problem with patience, I had just noticed after my publication that I was not in the right room, and having not found how to move it, I just deleted the old one to put it back the same but in the right living room.

Best regards,

Tainted Rajaion

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Fair enough - moderators (such as myself) can move messages if we notice that they are in the wrong place

In answer to your question, it does appear to be an issue with Dashboard Studio even in 9.0.1

You could try adding a trailing space to your format string so Splunk make the assumption that it is a timestamp

Tainted_Rajaion
Explorer

The space works well! It's subtle as a trick, I keep it warm, thank you very much for your help!

Tainted_Rajaion_0-1662638056646.png

 

Best regards,

Tainted Rajaion

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...