Reporting

Saved Searches from Before Splunk 6 Upgrade Display Differently

jodros
Builder

I noticed that after the Splunk 6 Upgrade, all of the saved searches displayed in what I called a "hybrid" format, where the new Splunk 6 feel exists on the upper part of the page, but starting at the search bar, it looks like Splunk 5. I think this might be due to older viewstates or possibly something in the savedsearches.conf. I have tried a few things but nothing seems to convert it fully to Splunk 6 look and feel.

Any suggestions would be appreciated.

Thanks

Tags (2)
0 Karma
1 Solution

jodros
Builder

I had to comment out the following lines in savedsearches.conf for my searches to display in the new Splunk 6 format:

#displayview = flashtimeline
#request.ui_dispatch_view = flashtimeline
#vsid = <some unique value>

After commenting out the vsid line, it auto gens a new one in both of the savedsearches.conf and viewstates.conf. I was not able to get the saved searches to display properly without commenting out all three of these lines. I originally thought just the vsid was the only thing that was needed, but it turns out they were all needed.

Thanks

View solution in original post

0 Karma

jodros
Builder

I had to comment out the following lines in savedsearches.conf for my searches to display in the new Splunk 6 format:

#displayview = flashtimeline
#request.ui_dispatch_view = flashtimeline
#vsid = <some unique value>

After commenting out the vsid line, it auto gens a new one in both of the savedsearches.conf and viewstates.conf. I was not able to get the saved searches to display properly without commenting out all three of these lines. I originally thought just the vsid was the only thing that was needed, but it turns out they were all needed.

Thanks

0 Karma

jtrucks
Splunk Employee
Splunk Employee

install a test instance of Splunk 6 on some spare system or VM. Then manually create the saved searches on that system and ingest just enough data to get at least a couple events (or more) in it for testing. See if you fix the problem. If so, you can be sure it's a localized issue on your prod system. I'd look for anything in */local directories, especially about viewstates.conf, ui-prefs.conf, and event_renderers.conf. There may be others, too...

--
Jesse Trucks
Minister of Magic
0 Karma

jodros
Builder

Afternoon bump.

0 Karma
Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...