<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Max Lines Value Update In Search &amp;amp; Reporting App in Security</title>
    <link>https://community.splunk.com/t5/Security/Max-Lines-Value-Update-In-Search-amp-Reporting-App/m-p/687597#M17867</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/79189"&gt;@deepakc&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thank you. It worked like a charm.&lt;/P&gt;</description>
    <pubDate>Wed, 15 May 2024 10:18:07 GMT</pubDate>
    <dc:creator>anandhalagaras1</dc:creator>
    <dc:date>2024-05-15T10:18:07Z</dc:date>
    <item>
      <title>Max Lines Value Update In Search &amp; Reporting App</title>
      <link>https://community.splunk.com/t5/Security/Max-Lines-Value-Update-In-Search-amp-Reporting-App/m-p/686164#M17799</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;Our Splunk Search heads are hosted in Cloud and managed by Support and currently we are running with the latest version (&lt;SPAN&gt;9.1.2308.203).&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This relates to the Max Lines configuration within the Format segment of the Search and Reporting App.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Previously, Splunk defaulted to displaying 20 or more lines in search results within the Search and Reporting App. As an administrator responsible for extracting Splunk logs across various applications over the years, I never found the need to expand concise search results to read all lines. However, in recent weeks, perhaps following an upgrade of the Splunk Search heads, I've noticed that each time I open a new Splunk search window or the existing Splunk tab times out and auto-refreshes, the Format &amp;gt; Max Lines option resets to 5. As a result, I consistently have to adjust it after nearly every search, which has become cumbersome.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Therefore, kindly provide guidance on changing the default value from 5 to 20 in the Search and Reporting App on Adhoc &amp;amp; ES Search heads. This adjustment would ease the inconvenience experienced by numerous customers and end-users who currently find it troublesome to customize it for each search.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The file is ui-prefs.conf, so I've filed a case with support to address this issue. Unfortunately, support wasn't able to make the necessary changes at the backend and suggested that I create a custom app and deploy it in the app upload section. Consequently, I created a custom app, deployed it, and it successfully passed the vetting process. Afterward, I restarted the Search head, but the changes didn't take effect.&lt;/P&gt;&lt;P&gt;Upon reaching out to support again, they were unable to provide a solution for the issue. Therefore, I require assistance in resolving this matter.&lt;/P&gt;&lt;P&gt;So refer the screenshot of the app which I have deployed for reference.&lt;/P&gt;&lt;P&gt;Created a app as below:&lt;/P&gt;&lt;P&gt;MaxLines_Values folder. Inside MaxLines_Value folder there would be default and metadata folder as mentioned in screenshot.&lt;/P&gt;&lt;P&gt;So kindly help on the same.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Max Lines Value.png" style="width: 365px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30642i4F1D2EFAF14C8342/image-size/large?v=v2&amp;amp;px=999" role="button" title="Max Lines Value.png" alt="Max Lines Value.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Default and MetaData Folder.png" style="width: 760px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30644i7956CB7AEEBFF56D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Default and MetaData Folder.png" alt="Default and MetaData Folder.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MaxLines_Values Folder.png" style="width: 834px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30643i823FB6C8CA84BE17/image-size/large?v=v2&amp;amp;px=999" role="button" title="MaxLines_Values Folder.png" alt="MaxLines_Values Folder.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ui prefs config.png" style="width: 372px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30645iF7E1112AACAA94C3/image-size/large?v=v2&amp;amp;px=999" role="button" title="ui prefs config.png" alt="ui prefs config.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 12:15:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Max-Lines-Value-Update-In-Search-amp-Reporting-App/m-p/686164#M17799</guid>
      <dc:creator>anandhalagaras1</dc:creator>
      <dc:date>2024-05-02T12:15:20Z</dc:date>
    </item>
    <item>
      <title>Re: Max Lines Value Update In Search &amp; Reporting App</title>
      <link>https://community.splunk.com/t5/Security/Max-Lines-Value-Update-In-Search-amp-Reporting-App/m-p/686190#M17801</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Maybe it’s not taking the settings due to app/config order precendece, run this to see you apps settings &lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rest splunk_server=local services/configs/conf-ui-prefs
| rename eai:appName AS app
| table app, disabled, display.events.maxLines, eai:acl.owner, eai:acl.perms.read, eai:acl.perms.write, eai:acl.sharing&lt;/LI-CODE&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;As these settings is in the search app&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;MaxLines_Values (YOUR_APP) &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;(This file needs to be ui-prefs.conf needs to be in the default folder in your app MaxLines_Values, it will then auto place it into local in cloud, make sure you update the version number so Splunk takes the new version as you already have it in there.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;/default/ui-prefs.conf&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[search]
display.events.maxLines = 20&lt;/LI-CODE&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Your meta data needs permissions &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;metatdata/default.meta&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[]
access = read : [ * ], write : [ admin, sc_admin]
export = system&lt;/LI-CODE&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I can’t test this as I don't have cloud, but worth a go, if that fails worth installing &lt;A href="https://splunkbase.splunk.com/app/6368" target="_blank"&gt;https://splunkbase.splunk.com/app/6368&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;As this can show app precedence order &lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| btool ui-prefs list --local&lt;/LI-CODE&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 15:58:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Max-Lines-Value-Update-In-Search-amp-Reporting-App/m-p/686190#M17801</guid>
      <dc:creator>deepakc</dc:creator>
      <dc:date>2024-05-02T15:58:25Z</dc:date>
    </item>
    <item>
      <title>Re: Max Lines Value Update In Search &amp; Reporting App</title>
      <link>https://community.splunk.com/t5/Security/Max-Lines-Value-Update-In-Search-amp-Reporting-App/m-p/687597#M17867</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/79189"&gt;@deepakc&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thank you. It worked like a charm.&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2024 10:18:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Max-Lines-Value-Update-In-Search-amp-Reporting-App/m-p/687597#M17867</guid>
      <dc:creator>anandhalagaras1</dc:creator>
      <dc:date>2024-05-15T10:18:07Z</dc:date>
    </item>
    <item>
      <title>Re: Max Lines Value Update In Search &amp; Reporting App</title>
      <link>https://community.splunk.com/t5/Security/Max-Lines-Value-Update-In-Search-amp-Reporting-App/m-p/687617#M17868</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/207926"&gt;@anandhalagaras1&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Glad it worked mate, and your welcome&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2024 13:16:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Max-Lines-Value-Update-In-Search-amp-Reporting-App/m-p/687617#M17868</guid>
      <dc:creator>deepakc</dc:creator>
      <dc:date>2024-05-15T13:16:25Z</dc:date>
    </item>
  </channel>
</rss>

