Splunk Search

Default visualisation for charts

dataisbeautiful
Communicator

Each time I run a search query and click visualisation, the default is "column chart".

How do I set this to default to "line chart" for myself, and how do I set this for other users?

Thanks in advance

Labels (1)
Tags (1)

star_lord
Explorer

@dataisbeautiful 

You should be able to control this by adding this line:

display.visualizations.charting.chart = line


to the following .conf file(s):

Global:

$SPLUNK_HOME/etc/system/local/ui-prefs.conf


Per User:

$SPLUNK_HOME/etc/users/<username>/system/local/ui-prefs.conf


For more information see:
https://docs.splunk.com/Documentation/Splunk/9.3.1/admin/Ui-prefsconf

0 Karma
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...