Reporting

Saved Searches from Before Splunk 6 Upgrade Display Differently

jodros
Builder

I noticed that after the Splunk 6 Upgrade, all of the saved searches displayed in what I called a "hybrid" format, where the new Splunk 6 feel exists on the upper part of the page, but starting at the search bar, it looks like Splunk 5. I think this might be due to older viewstates or possibly something in the savedsearches.conf. I have tried a few things but nothing seems to convert it fully to Splunk 6 look and feel.

Any suggestions would be appreciated.

Thanks

Tags (2)
0 Karma
1 Solution

jodros
Builder

I had to comment out the following lines in savedsearches.conf for my searches to display in the new Splunk 6 format:

#displayview = flashtimeline
#request.ui_dispatch_view = flashtimeline
#vsid = <some unique value>

After commenting out the vsid line, it auto gens a new one in both of the savedsearches.conf and viewstates.conf. I was not able to get the saved searches to display properly without commenting out all three of these lines. I originally thought just the vsid was the only thing that was needed, but it turns out they were all needed.

Thanks

View solution in original post

0 Karma

jodros
Builder

I had to comment out the following lines in savedsearches.conf for my searches to display in the new Splunk 6 format:

#displayview = flashtimeline
#request.ui_dispatch_view = flashtimeline
#vsid = <some unique value>

After commenting out the vsid line, it auto gens a new one in both of the savedsearches.conf and viewstates.conf. I was not able to get the saved searches to display properly without commenting out all three of these lines. I originally thought just the vsid was the only thing that was needed, but it turns out they were all needed.

Thanks

0 Karma

jtrucks
Splunk Employee
Splunk Employee

install a test instance of Splunk 6 on some spare system or VM. Then manually create the saved searches on that system and ingest just enough data to get at least a couple events (or more) in it for testing. See if you fix the problem. If so, you can be sure it's a localized issue on your prod system. I'd look for anything in */local directories, especially about viewstates.conf, ui-prefs.conf, and event_renderers.conf. There may be others, too...

--
Jesse Trucks
Minister of Magic
0 Karma

jodros
Builder

Afternoon bump.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...