Splunk Search

Generic Host search only uses "all time"

MasterOogway
Communicator

When I choose a host from the Host list it automatically starts to search......but for "all time". I don't want to search for "all time". What xml file do you change to modify the initial search from "all time" to say...60 minutes or 15 minutes?

Tags (1)

briang67
Communicator

Not sure if this is the best way, but I've done this for the search app by editing $SPLUNK_HOME/etc/apps/search/default/data/ui/views/flashtimeline.xml and changed the "selected" parameter to something other than "All time".

MasterOogway
Communicator

I tried a multiple of different "time" changes:
'in the last two hours'
'two hours'
'in the last 15 minutes'

all to no avail. What timeline specifications did you use?
Thanks.

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...