Deployment Architecture

Why is my timezone configuration in the app directory for my search head cluster being ignored?

wweiland
Contributor

I'm trying to set the timezone via a deployable app to my search head cluster. If I put the configuration in the etc/system/local, it works fine. If it's in the app directory, then it doesn't. I did have a user-prefs.conf in my etc/users directory, but it didn't have the TZ config present and I took it a step further and deleted it. Using find and grep, the file in apps is the only user-prefs.conf that has TZ in it. Can anyone shed light on why Splunk would ignore the configuration even though it shows up in btool?

PS, this is a shcluster, so that's why the file is in default.

TIA,
Todd

Works

/opt/sh2a/etc/system/local/user-prefs.conf [general]
/opt/sh2a/etc/system/local/user-prefs.conf tz = America/New_York
/opt/sh2a/etc/apps/user-prefs/default/user-prefs.conf [general_default]
/opt/sh2a/etc/apps/user-prefs/default/user-prefs.conf appOrder = search
/opt/sh2a/etc/apps/user-prefs/default/user-prefs.conf default_namespace = $default
/opt/sh2a/etc/apps/user-prefs/default/user-prefs.conf showWhatsNew = 1

Doesn't work

/opt/sh2a/etc/apps/all_sh_base/default/user-prefs.conf [general]
/opt/sh2a/etc/apps/all_sh_base/default/user-prefs.conf tz = America/New_York
/opt/sh2a/etc/apps/user-prefs/default/user-prefs.conf [general_default]
/opt/sh2a/etc/apps/user-prefs/default/user-prefs.conf appOrder = search
/opt/sh2a/etc/apps/user-prefs/default/user-prefs.conf default_namespace = $default
/opt/sh2a/etc/apps/user-prefs/default/user-prefs.conf showWhatsNew = 1

0 Karma
1 Solution

lycollicott
Motivator

Cool. My first forum cross-reference. 🙂

wweiland
Contributor

Interesting, I'll try and make my app global. Thank you for pointing out that post.

0 Karma

wweiland
Contributor

Setting the app to global worked. Thanks!

0 Karma

lguinn2
Legend

So there is an actual app that is distributed with Splunk named user-prefs

$SPLUNK_HOME/etc/apps/user-prefs

I believe that this app gets some special treatment, that affects the order of precedence. See this description of user-prefs.conf in the Admin manual.

0 Karma

wweiland
Contributor

Same problem with the ui-prefs.conf too. Ended up making a link and it seems to be working, but it doesn't make sense.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...