Splunk Search

Default visualisation for charts

dataisbeautiful
Path Finder

Each time I run a search query and click visualisation, the default is "column chart".

How do I set this to default to "line chart" for myself, and how do I set this for other users?

Thanks in advance

Labels (1)
Tags (1)

star_lord
Explorer

@dataisbeautiful 

You should be able to control this by adding this line:

display.visualizations.charting.chart = line


to the following .conf file(s):

Global:

$SPLUNK_HOME/etc/system/local/ui-prefs.conf


Per User:

$SPLUNK_HOME/etc/users/<username>/system/local/ui-prefs.conf


For more information see:
https://docs.splunk.com/Documentation/Splunk/9.3.1/admin/Ui-prefsconf

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...