Installation
Highlighted

Splunk 6 upgrade breaks timepicker in dash amongst other things.

Path Finder

Hi all,

I just upgraded Splunk to the new version 6.0 on a test server with all our apps on, and it seems that the timepicker isn't working on any of our dashboards. It's just defaulting to "All Time". I tried deleting the timepicker and re-adding from the editor but still no joy. Am I missing something here? All the panels are just standard saved searches (or "reports" as they now seem to be called). I tried making a new dash but still have the same issue.

Also, custom styles are completely gone - for example, Cisco Security Suite tries to load the custom styles, then you see it getting overriden by the default grey theme. This seems to be a result of the CSS changes in the documentation though. Hopefully I can fix that easily. 🙂

Am I missing something here? Has anyone else seen the timepicker issue? The upgrade was coming from 5.0.3.

0 Karma
Highlighted

Re: Splunk 6 upgrade breaks timepicker in dash amongst other things.

Super Champion

There's some info about CSS and other good pointers for developers in the Changes for Splunk App developers topic in the Installation Manual. Not quite sure what's up with the time picker, though, especially if you added it back from the editor and it's still not working...sorry.

0 Karma
Highlighted

Re: Splunk 6 upgrade breaks timepicker in dash amongst other things.

Path Finder

Hrm, I reverted the test system anyhow. I'm going to spin up another test system and see if I can replicate this. It's a bit unnerving to say the least. I wonder if the upgrade has done something with the saved searches to stop the time picker from having any effect, I didn't think about that at the time.

Call me a little over-cautious but anything with a .0 version number makes me nervous! 😛

0 Karma
Highlighted

Re: Splunk 6 upgrade breaks timepicker in dash amongst other things.

Contributor

There's a Splunk education video on Creating dashboards for Version 6. At about 5 min 30 into the video it talks about adding the timepicker and the need to convert the searches in each of the panels on the dashboard to be inline searches. Could this be related to your problem?

Dave

View solution in original post

Highlighted

Re: Splunk 6 upgrade breaks timepicker in dash amongst other things.

Path Finder

Yes, thanks! That seems to be the issue with the timepicker.... Cloning all of them to inline and removing the relevant XML has sorted it. I understand what's happening now - the search string is embedded in the dashboard rather than just being a reference to a saved search.

Not sure how I feel about this in all honesty. Being able to refer to saved searches means that if you have the same search in different dashboards presented a different way, you only need to change the search in a single location.

Looks like I've got work to do on the test box before exporting my apps out again!

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.