Installation

Splunk 6 upgrade breaks timepicker in dash amongst other things.

Narj
Path Finder

Hi all,

I just upgraded Splunk to the new version 6.0 on a test server with all our apps on, and it seems that the timepicker isn't working on any of our dashboards. It's just defaulting to "All Time". I tried deleting the timepicker and re-adding from the editor but still no joy. Am I missing something here? All the panels are just standard saved searches (or "reports" as they now seem to be called). I tried making a new dash but still have the same issue.

Also, custom styles are completely gone - for example, Cisco Security Suite tries to load the custom styles, then you see it getting overriden by the default grey theme. This seems to be a result of the CSS changes in the documentation though. Hopefully I can fix that easily. 🙂

Am I missing something here? Has anyone else seen the timepicker issue? The upgrade was coming from 5.0.3.

0 Karma
1 Solution

davebrooking
Contributor

There's a Splunk education video on Creating dashboards for Version 6. At about 5 min 30 into the video it talks about adding the timepicker and the need to convert the searches in each of the panels on the dashboard to be inline searches. Could this be related to your problem?

Dave

View solution in original post

davebrooking
Contributor

There's a Splunk education video on Creating dashboards for Version 6. At about 5 min 30 into the video it talks about adding the timepicker and the need to convert the searches in each of the panels on the dashboard to be inline searches. Could this be related to your problem?

Dave

Narj
Path Finder

Yes, thanks! That seems to be the issue with the timepicker.... Cloning all of them to inline and removing the relevant XML has sorted it. I understand what's happening now - the search string is embedded in the dashboard rather than just being a reference to a saved search.

Not sure how I feel about this in all honesty. Being able to refer to saved searches means that if you have the same search in different dashboards presented a different way, you only need to change the search in a single location.

Looks like I've got work to do on the test box before exporting my apps out again!

0 Karma

ChrisG
Splunk Employee
Splunk Employee

There's some info about CSS and other good pointers for developers in the Changes for Splunk App developers topic in the Installation Manual. Not quite sure what's up with the time picker, though, especially if you added it back from the editor and it's still not working...sorry.

0 Karma

Narj
Path Finder

Hrm, I reverted the test system anyhow. I'm going to spin up another test system and see if I can replicate this. It's a bit unnerving to say the least. I wonder if the upgrade has done something with the saved searches to stop the time picker from having any effect, I didn't think about that at the time.

Call me a little over-cautious but anything with a .0 version number makes me nervous! 😛

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...