<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic default.xml customization in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/default-xml-customization/m-p/100863#M21116</link>
    <description>&lt;P&gt;I would like to ask a question in relation to the Cisco Security app. I got version 1.0.1. I would like to be able to customize the bar just below the splunk logo&lt;/P&gt;

&lt;P&gt;It appears that I cannot change it by putting the default.xml under &lt;CODE&gt;C:\Program Files\Splunk\etc\apps\Splunk_CiscoSecuritySuite\local\data\ui\nav&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;I had to edit the copy in &lt;CODE&gt;C:\Program Files\Splunk\etc\apps\Splunk_CiscoSecuritySuite\default\data\ui\nav&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;to customize it, there's not much about how to work it. Where should I start?&lt;/P&gt;

&lt;P&gt;Here is an extract of what happened when I restart splunk to enable the changes?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;C:\Program Files\Splunk\bin&amp;gt;splunk start

Splunk&amp;gt; Needle. Haystack. Found.
Checking prerequisites...
        Checking http port [8000]: open
        Checking mgmt port [8089]: open

        Checking configuration... Error while parsing 'C:\Program Files\Splunk\etc\apps\Splunk_CiscoSecuritySuite\default\data\ui\nav\_default.xml': mismatched tag: line 95, column 2

There were problems with the configuration files.

Would you like to ignore these errors? [y/n]:y

Done.
        Checking index directory...
        Validated databases: _audit _blocksignature _internal _thefishbucket history main summary

Done
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Mon, 31 Oct 2011 05:28:20 GMT</pubDate>
    <dc:creator>e82than</dc:creator>
    <dc:date>2011-10-31T05:28:20Z</dc:date>
    <item>
      <title>default.xml customization</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/default-xml-customization/m-p/100863#M21116</link>
      <description>&lt;P&gt;I would like to ask a question in relation to the Cisco Security app. I got version 1.0.1. I would like to be able to customize the bar just below the splunk logo&lt;/P&gt;

&lt;P&gt;It appears that I cannot change it by putting the default.xml under &lt;CODE&gt;C:\Program Files\Splunk\etc\apps\Splunk_CiscoSecuritySuite\local\data\ui\nav&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;I had to edit the copy in &lt;CODE&gt;C:\Program Files\Splunk\etc\apps\Splunk_CiscoSecuritySuite\default\data\ui\nav&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;to customize it, there's not much about how to work it. Where should I start?&lt;/P&gt;

&lt;P&gt;Here is an extract of what happened when I restart splunk to enable the changes?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;C:\Program Files\Splunk\bin&amp;gt;splunk start

Splunk&amp;gt; Needle. Haystack. Found.
Checking prerequisites...
        Checking http port [8000]: open
        Checking mgmt port [8089]: open

        Checking configuration... Error while parsing 'C:\Program Files\Splunk\etc\apps\Splunk_CiscoSecuritySuite\default\data\ui\nav\_default.xml': mismatched tag: line 95, column 2

There were problems with the configuration files.

Would you like to ignore these errors? [y/n]:y

Done.
        Checking index directory...
        Validated databases: _audit _blocksignature _internal _thefishbucket history main summary

Done
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 31 Oct 2011 05:28:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/default-xml-customization/m-p/100863#M21116</guid>
      <dc:creator>e82than</dc:creator>
      <dc:date>2011-10-31T05:28:20Z</dc:date>
    </item>
    <item>
      <title>Re: default.xml customization</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/default-xml-customization/m-p/100864#M21117</link>
      <description>&lt;P&gt;i really think the ninjas are too busy at splunk. I often had to ask a question and answer it myself. Even after sending it to splunk support. Nothing came back. It's as good as not having splunk support set up.&lt;/P&gt;

&lt;P&gt;Ok, how i fixed my own problem. It's best you have the app installed (and inside it) and edit from &lt;CODE&gt;User Interface -&amp;gt; Navigation -&amp;gt; default.xml&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Chances are that if you try to edit the files via the $SPLUNK_HOME directory, you're going to get yourself in a real mess. The Splunk Manager, if you can get to it will be a better place to edit the files. Use an admin account and make sure the app permission is app. be it read or write, it's up to you.&lt;/P&gt;

&lt;P&gt;I tried to do via the files then i was informed by the asia's splunk support: Lye-Hee to do it via the UI and i got it.&lt;/P&gt;

&lt;P&gt;Thanks all for your kind attention to even bother reading my questions. The 54 of you guys! Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2011 07:52:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/default-xml-customization/m-p/100864#M21117</guid>
      <dc:creator>e82than</dc:creator>
      <dc:date>2011-11-02T07:52:02Z</dc:date>
    </item>
    <item>
      <title>Re: default.xml customization</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/default-xml-customization/m-p/100865#M21118</link>
      <description>&lt;P&gt;an upvote for your efforts&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jun 2012 19:00:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/default-xml-customization/m-p/100865#M21118</guid>
      <dc:creator>anssntaco</dc:creator>
      <dc:date>2012-06-19T19:00:38Z</dc:date>
    </item>
  </channel>
</rss>

