Dashboards & Visualizations

Splunk v6.0.4 - Timepicker Preset Missing - "Yesterday"

BP9906
Builder

Hello,
Ever since our upgrade to v6 from v5, the "Yesterday" timepicker preset is missing. I see its not a default option yet it exists in times.conf. Can someone clarify why its missing?

I see this known bug which is perhaps related:
The times.conf spec file still refers to adding submenus in order to customize time range presets; this feature does not exist in Splunk Enterprise 6.x (SPL-76798)

0 Karma

BP9906
Builder

Resolved in v6.0.6

0 Karma

BP9906
Builder

Resolved in v6.0.6

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

I've managed to replicate this - it's related to adding a larger number of custom time range presets. After adding the sixth I see Yesterday disappear, five work fine. You've added eight, so by that logic three should be missing... and indeed, you're missing Yesterday, Year to date, and Week to date - three time ranges off the bottom of the alphabetical order are missing.

This bug is still present in 6.1.1 and not on the list of known issues so please open a support case referencing this answers page.

yannK
Splunk Employee
Splunk Employee

Opened as bug SPL-86219, and added to known issues.
Thanks guys.

martin_mueller
SplunkTrust
SplunkTrust

As a workaround, you should be able to disable a few rarely used time ranges to get Yesterday back.

0 Karma

BP9906
Builder

Splunk v6.0.4

I dont appear to have it, and I see it present in my system/local/times.conf and system/default/times.conf. The first column of "relative" under Presets is the same as the picture in v6.0.4 documentation: http://docs.splunk.com/Documentation/Splunk/6.0.4/SearchTutorial/Aboutthetimerangepicker

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Yesterday should be present in the middle of the second column ("Relative") of the presets section.

The known bug shouldn't be related.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Splunk is officially part of Cisco

Revolutionizing how our customers build resilience across their entire digital footprint.   Splunk ...

Splunk APM & RUM | Planned Maintenance March 26 - March 28, 2024

There will be planned maintenance for Splunk APM and RUM between March 26, 2024 and March 28, 2024 as ...