<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic how to disable &amp;quot;ALL time&amp;quot; for user role in Security</title>
    <link>https://community.splunk.com/t5/Security/how-to-disable-quot-ALL-time-quot-for-user-role/m-p/360115#M9012</link>
    <description>&lt;P&gt;hello &lt;/P&gt;

&lt;P&gt;i have created a customized role &lt;STRONG&gt;simple_user&lt;/STRONG&gt; and assigned users to. i also wanted to disable &lt;STRONG&gt;"all time"&lt;/STRONG&gt; option from search bar for the user in &lt;STRONG&gt;simple_user&lt;/STRONG&gt; role. &lt;/P&gt;

&lt;P&gt;can any one help me how to configure it?&lt;/P&gt;</description>
    <pubDate>Tue, 02 May 2017 21:50:59 GMT</pubDate>
    <dc:creator>AzmathShaik</dc:creator>
    <dc:date>2017-05-02T21:50:59Z</dc:date>
    <item>
      <title>how to disable "ALL time" for user role</title>
      <link>https://community.splunk.com/t5/Security/how-to-disable-quot-ALL-time-quot-for-user-role/m-p/360115#M9012</link>
      <description>&lt;P&gt;hello &lt;/P&gt;

&lt;P&gt;i have created a customized role &lt;STRONG&gt;simple_user&lt;/STRONG&gt; and assigned users to. i also wanted to disable &lt;STRONG&gt;"all time"&lt;/STRONG&gt; option from search bar for the user in &lt;STRONG&gt;simple_user&lt;/STRONG&gt; role. &lt;/P&gt;

&lt;P&gt;can any one help me how to configure it?&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2017 21:50:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/how-to-disable-quot-ALL-time-quot-for-user-role/m-p/360115#M9012</guid>
      <dc:creator>AzmathShaik</dc:creator>
      <dc:date>2017-05-02T21:50:59Z</dc:date>
    </item>
    <item>
      <title>Re: how to disable "ALL time" for user role</title>
      <link>https://community.splunk.com/t5/Security/how-to-disable-quot-ALL-time-quot-for-user-role/m-p/360116#M9013</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;

&lt;P&gt;Not exactly what you're after but you can set the maximum time window for a search using &lt;CODE&gt;srchTimeWin = &amp;lt;time_in_seconds&amp;gt;&lt;/CODE&gt; in authorize.conf.&lt;/P&gt;

&lt;P&gt;For example, if you didn't want anyone with the simple_user role to be able to search a timeframe over a year then you would add the following:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;[role_simple_user]&lt;BR /&gt;
srchTimeWin = 31536000&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Note that the stanza title is in the format &lt;CODE&gt;role_&amp;lt;role_name&amp;gt;&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2017 12:16:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/how-to-disable-quot-ALL-time-quot-for-user-role/m-p/360116#M9013</guid>
      <dc:creator>hhGA</dc:creator>
      <dc:date>2017-05-03T12:16:40Z</dc:date>
    </item>
    <item>
      <title>Re: how to disable "ALL time" for user role</title>
      <link>https://community.splunk.com/t5/Security/how-to-disable-quot-ALL-time-quot-for-user-role/m-p/360117#M9014</link>
      <description>&lt;P&gt;Thanks your answer helped me.&lt;/P&gt;

&lt;P&gt;but i don't want to show the option of All Time for users except ADMIN user. is it possible??&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2017 14:18:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/how-to-disable-quot-ALL-time-quot-for-user-role/m-p/360117#M9014</guid>
      <dc:creator>AzmathShaik</dc:creator>
      <dc:date>2017-05-03T14:18:00Z</dc:date>
    </item>
    <item>
      <title>Re: how to disable "ALL time" for user role</title>
      <link>https://community.splunk.com/t5/Security/how-to-disable-quot-ALL-time-quot-for-user-role/m-p/360118#M9015</link>
      <description>&lt;P&gt;You're welcome.&lt;/P&gt;

&lt;P&gt;Unfortunately I am not aware of an configuration in Splunk that allows you to do that.&lt;/P&gt;

&lt;P&gt;You can remove it from dashboards, but not from searches / reports.&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2017 14:20:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/how-to-disable-quot-ALL-time-quot-for-user-role/m-p/360118#M9015</guid>
      <dc:creator>hhGA</dc:creator>
      <dc:date>2017-05-03T14:20:24Z</dc:date>
    </item>
  </channel>
</rss>

