Reporting

Saved Searches from Before Splunk 6 Upgrade Display Differently

jodros
Builder

I noticed that after the Splunk 6 Upgrade, all of the saved searches displayed in what I called a "hybrid" format, where the new Splunk 6 feel exists on the upper part of the page, but starting at the search bar, it looks like Splunk 5. I think this might be due to older viewstates or possibly something in the savedsearches.conf. I have tried a few things but nothing seems to convert it fully to Splunk 6 look and feel.

Any suggestions would be appreciated.

Thanks

Tags (2)
0 Karma
1 Solution

jodros
Builder

I had to comment out the following lines in savedsearches.conf for my searches to display in the new Splunk 6 format:

#displayview = flashtimeline
#request.ui_dispatch_view = flashtimeline
#vsid = <some unique value>

After commenting out the vsid line, it auto gens a new one in both of the savedsearches.conf and viewstates.conf. I was not able to get the saved searches to display properly without commenting out all three of these lines. I originally thought just the vsid was the only thing that was needed, but it turns out they were all needed.

Thanks

View solution in original post

0 Karma

jodros
Builder

I had to comment out the following lines in savedsearches.conf for my searches to display in the new Splunk 6 format:

#displayview = flashtimeline
#request.ui_dispatch_view = flashtimeline
#vsid = <some unique value>

After commenting out the vsid line, it auto gens a new one in both of the savedsearches.conf and viewstates.conf. I was not able to get the saved searches to display properly without commenting out all three of these lines. I originally thought just the vsid was the only thing that was needed, but it turns out they were all needed.

Thanks

0 Karma

jtrucks
Splunk Employee
Splunk Employee

install a test instance of Splunk 6 on some spare system or VM. Then manually create the saved searches on that system and ingest just enough data to get at least a couple events (or more) in it for testing. See if you fix the problem. If so, you can be sure it's a localized issue on your prod system. I'd look for anything in */local directories, especially about viewstates.conf, ui-prefs.conf, and event_renderers.conf. There may be others, too...

--
Jesse Trucks
Minister of Magic
0 Karma

jodros
Builder

Afternoon bump.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...