Splunk Search

I need to set 24hours default search intervals for user role

jayakumar89
Explorer

We have 3 custom roles (user, power user and admin) and i would like to set 24hours as default search interval or block all time option only for all users who are mapped to user role. Any help would be appreciated.

TIA
Jay

Tags (1)
0 Karma
1 Solution

adonio
Ultra Champion

Hi jayakumar89,
using the setting highlighted in the attached picture you can prevent from users under a certain role from searching past a certain time
you can also set ui-pref.conf to set default search time. some related answers here:
https://answers.splunk.com/answers/106136/how-to-set-the-default-search-time-in-splunk-6.html
https://answers.splunk.com/answers/105781/splunk-6-0-default-time-in-time-picker.html
more on ui-pref.conf here:
https://docs.splunk.com/Documentation/Splunk/6.5.2/Admin/Ui-prefsconf![alt text]1

alt text

View solution in original post

adonio
Ultra Champion

Hi jayakumar89,
using the setting highlighted in the attached picture you can prevent from users under a certain role from searching past a certain time
you can also set ui-pref.conf to set default search time. some related answers here:
https://answers.splunk.com/answers/106136/how-to-set-the-default-search-time-in-splunk-6.html
https://answers.splunk.com/answers/105781/splunk-6-0-default-time-in-time-picker.html
more on ui-pref.conf here:
https://docs.splunk.com/Documentation/Splunk/6.5.2/Admin/Ui-prefsconf![alt text]1

alt text

jayakumar89
Explorer

Thanks for the info. Is it possible to make users does not have All time option at all ?

0 Karma

woodcock
Esteemed Legend

Yes, you create a .../local/times.conf that has this content:

[all_time]
disabled = 1
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...