All Apps and Add-ons

PostProcess show one hour data on Splunk for Active Directory app

bruno_marchetti
Engager

Splunk for Active Directory app installed, datas available.
Everything is fine but when I change range date in > Security > User Utilization (sec_user_utilization.xml), graph is modified (from one hour to 4 hours for exemple) but show only one hour data. The problem seem to be with PostProcess and TimeRangePicker modules. This search work well with flashtimeline. Is it normal?

synodineios
Explorer

Hey there!It seems i'm facing the same problem as yours and i was wondering if you found a solution to this.I can't find anything related on web or here!

0 Karma

bruno_marchetti
Engager

No solution yet. It's in progress with Splunk support.

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...