Splunk Search

Fast mode being set automatically

gmuller1
Engager

I always use Verbose mode
Sometimes I open splunk and it is set as Fast mode as default, why is splunk switching from verbose to fast mode without my consent? Is this a setting where I can change? I've made a search but couldn't find.

Tags (1)
0 Karma
1 Solution

chrisyounger
SplunkTrust
SplunkTrust

Dashboard searches (and other searches like this) always run in fast mode. So if you click the little magnifying glass to "break out" a search from a dashboard then it will carry-over that setting to your search pane. This is probably whats happening to you.

If you do set Smart/verbose mode, it does get saved in your personal settings directory, but only on a PER-APP basis. I expect this, coupled with the dashboard searches I mentioned above, means you will find yourself changing the search mode setting regularly.

I don't believe there is any way to change this behaviour.

All the best.

View solution in original post

gmuller1
Engager

Thanks all for the answers.

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi gmuller1,

you can set a default search mode by using a ui-prefs.conf setting with this:

[default] 
display.page.search.mode = [fast|smart|verbose]

choose what ever mode you want as default, put it into $SPLUNK_HOME/etc/system/local/ and restart Splunk.

This should set the default search mode, but only until you change it again in the UI then it is saved in your session cookie.

Hope this helps ...

cheers, MuS

0 Karma

rashi83
Path Finder

Hi,

I have changed the said file to 

[default]
display.page.search.mode = [smart]

 

Location of file : C:\Program Files\Splunk\etc\system\local

But still UI is showing default as VERBOSE.

 

0 Karma

chrisyounger
SplunkTrust
SplunkTrust

Dashboard searches (and other searches like this) always run in fast mode. So if you click the little magnifying glass to "break out" a search from a dashboard then it will carry-over that setting to your search pane. This is probably whats happening to you.

If you do set Smart/verbose mode, it does get saved in your personal settings directory, but only on a PER-APP basis. I expect this, coupled with the dashboard searches I mentioned above, means you will find yourself changing the search mode setting regularly.

I don't believe there is any way to change this behaviour.

All the best.

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...