Installation

Search Syntax Highlighting - Free License - 6.5.0

gvmorley
Contributor

Hi,

Does anyone know how to enable the new 'Search Syntax Highlighting' and 'Compact' Assistant features when using the Free License?

The Splunk Overview 6.5 App has a section which says that these can be enabled from your 'Account settings' page. Something which isn't accessible with the Free License!

I've checked in: etc/apps/user-prefs/default/user-prefs.conf

And these options are included:

[general]
search_syntax_highlighting = 1
search_assistant = compact

But they don't appear to be working. I've checked in: /opt/splunk/etc/users/admin/user-prefs/local/user-prefs.conf to see if the options are being disabled, but they're not.

I've also tried adding the options into that file (/opt/splunk/etc/users/admin/user-prefs/local/user-prefs.conf) and restarting, but still no luck.

I have also tried using both Safari (10.0) and Chrome (53.0.2785.116) to see if it was browser related, but both behave the same.

This 6.5.0 install was an upgrade from 6.4.3 (already set-up using the Free License).

These look like great features, so if anyone has thoughts on how to get them going, that would be great.

Tags (2)
1 Solution

ChrisG
Splunk Employee
Splunk Employee

Engineering has confirmed that this is a bug, it should be fixed in a forthcoming maintenance release.

View solution in original post

gvmorley
Contributor

Hi All,

I'm very pleased to say that this all appears to be resolved in version 6.5.1

Thanks to the Splunk Team.

lakromani
Builder

Ahh, Not only me.
I did posted this some days ago.
https://answers.splunk.com/answers/455118/syntax-highlighting-and-autocomplete-in-your-accou.html
Also did an upgrade.

0 Karma

fredyj
Engager
0 Karma

lakromani
Builder

Problem is that in Free License mode, you can not click on the user.
There are no button to the left of Messages.

0 Karma

ChrisG
Splunk Employee
Splunk Employee

Engineering has confirmed that this is a bug, it should be fixed in a forthcoming maintenance release.

gvmorley
Contributor

Hi Chris. Thanks for coming back to me on this; it's good to know that it's not just me! 6.5.0 is still a great release, so will keep a lookout for the maintenance patch.

0 Karma

ChrisG
Splunk Employee
Splunk Employee

Syntax highlighting should be turned on by default. Was that not the case when you installed? The account settings page is where you go if you want to disable it. Or that's how it's supposed to work. I am reading Syntax highlighting in the Search Manual, and it has been on by default in the demos I have seen.

0 Karma

gvmorley
Contributor

Hi Chris.

Unfortunately is doesn't appear to be working. I agree with you that 'it should' be on by default and the settings in etc/apps/user-prefs/default/user-prefs.conf (shown above), suggest that it is.

But it's not working for me.

Happy to share configs or work with someone to investigate further. I can only guess that it's 'upgrade' (from 6.4.3) or 'Free License' (as this doesn't allow user context configuration) related.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...