Dashboards & Visualizations

Change metrics workspace default lookback time

brabagaza
Explorer

Hi all,
I was wondering if anyone knew of a way to reset default search time period inside the metrics workspace.

metrics_workspace1.PNG

The default seems to be an hour, which is independent of default period set in the
$SPLUNK_HOME/etc/system/local/ui-prefs.conf file which I've set to 1 day

[search]
dispatch.earliest_time = 1d@d
dispatch.latest_time = now

metrics_workspace2.PNG

options that are provided in the config in
/opt/splunk/etc/apps/splunk_metrics_workspace/README/workspace.conf.example

seem to provide a lookback option
[metadata]
earliest = -1d

but this does not affect the lookback time indicate earlier.

Also the /opt/splunk/etc/apps/splunk_metrics_workspace/README/workspace.conf.spec
option does not seems to change the default -1hour lookback

[metadata]
earliest = -1m
#* Sets how far back to query the metrics catalog.
#* Shortening this could speed up the catalog query.
#* Default: -2d (?default seems to be 1 hour)

Does not change the default time,  beyond the README folder documentation seems limited, any help is appreciated,
Roelof
@fcannon_splunk
@kvarnun_splunk

Labels (1)
0 Karma

elizabethl_splu
Splunk Employee
Splunk Employee

Hi @brabagaza  thanks for flagging this bug! We're now tracking it and plan to fix it. 

0 Karma

brabagaza
Explorer

Hi @elizabethl_splu , great to year it's being fixed, is there any place that I might be able to track the status?

Cheers

R

0 Karma
Get Updates on the Splunk Community!

Routing Data to Different Splunk Indexes in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...

Getting Started with AIOps: Event Correlation Basics and Alert Storm Detection in ...

Getting Started with AIOps:Event Correlation Basics and Alert Storm Detection in Splunk IT Service ...

Register to Attend BSides SPL 2022 - It's all Happening October 18!

Join like-minded individuals for technical sessions on everything Splunk!  This is a community-led and run ...