Reporting

Saved Searches from Before Splunk 6 Upgrade Display Differently

jodros
Builder

I noticed that after the Splunk 6 Upgrade, all of the saved searches displayed in what I called a "hybrid" format, where the new Splunk 6 feel exists on the upper part of the page, but starting at the search bar, it looks like Splunk 5. I think this might be due to older viewstates or possibly something in the savedsearches.conf. I have tried a few things but nothing seems to convert it fully to Splunk 6 look and feel.

Any suggestions would be appreciated.

Thanks

Tags (2)
0 Karma
1 Solution

jodros
Builder

I had to comment out the following lines in savedsearches.conf for my searches to display in the new Splunk 6 format:

#displayview = flashtimeline
#request.ui_dispatch_view = flashtimeline
#vsid = <some unique value>

After commenting out the vsid line, it auto gens a new one in both of the savedsearches.conf and viewstates.conf. I was not able to get the saved searches to display properly without commenting out all three of these lines. I originally thought just the vsid was the only thing that was needed, but it turns out they were all needed.

Thanks

View solution in original post

0 Karma

jodros
Builder

I had to comment out the following lines in savedsearches.conf for my searches to display in the new Splunk 6 format:

#displayview = flashtimeline
#request.ui_dispatch_view = flashtimeline
#vsid = <some unique value>

After commenting out the vsid line, it auto gens a new one in both of the savedsearches.conf and viewstates.conf. I was not able to get the saved searches to display properly without commenting out all three of these lines. I originally thought just the vsid was the only thing that was needed, but it turns out they were all needed.

Thanks

0 Karma

jtrucks
Splunk Employee
Splunk Employee

install a test instance of Splunk 6 on some spare system or VM. Then manually create the saved searches on that system and ingest just enough data to get at least a couple events (or more) in it for testing. See if you fix the problem. If so, you can be sure it's a localized issue on your prod system. I'd look for anything in */local directories, especially about viewstates.conf, ui-prefs.conf, and event_renderers.conf. There may be others, too...

--
Jesse Trucks
Minister of Magic
0 Karma

jodros
Builder

Afternoon bump.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...