Reporting

Saved Searches from Before Splunk 6 Upgrade Display Differently

jodros
Builder

I noticed that after the Splunk 6 Upgrade, all of the saved searches displayed in what I called a "hybrid" format, where the new Splunk 6 feel exists on the upper part of the page, but starting at the search bar, it looks like Splunk 5. I think this might be due to older viewstates or possibly something in the savedsearches.conf. I have tried a few things but nothing seems to convert it fully to Splunk 6 look and feel.

Any suggestions would be appreciated.

Thanks

Tags (2)
0 Karma
1 Solution

jodros
Builder

I had to comment out the following lines in savedsearches.conf for my searches to display in the new Splunk 6 format:

#displayview = flashtimeline
#request.ui_dispatch_view = flashtimeline
#vsid = <some unique value>

After commenting out the vsid line, it auto gens a new one in both of the savedsearches.conf and viewstates.conf. I was not able to get the saved searches to display properly without commenting out all three of these lines. I originally thought just the vsid was the only thing that was needed, but it turns out they were all needed.

Thanks

View solution in original post

0 Karma

jodros
Builder

I had to comment out the following lines in savedsearches.conf for my searches to display in the new Splunk 6 format:

#displayview = flashtimeline
#request.ui_dispatch_view = flashtimeline
#vsid = <some unique value>

After commenting out the vsid line, it auto gens a new one in both of the savedsearches.conf and viewstates.conf. I was not able to get the saved searches to display properly without commenting out all three of these lines. I originally thought just the vsid was the only thing that was needed, but it turns out they were all needed.

Thanks

0 Karma

jtrucks
Splunk Employee
Splunk Employee

install a test instance of Splunk 6 on some spare system or VM. Then manually create the saved searches on that system and ingest just enough data to get at least a couple events (or more) in it for testing. See if you fix the problem. If so, you can be sure it's a localized issue on your prod system. I'd look for anything in */local directories, especially about viewstates.conf, ui-prefs.conf, and event_renderers.conf. There may be others, too...

--
Jesse Trucks
Minister of Magic
0 Karma

jodros
Builder

Afternoon bump.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...