Security

How do I set default conf files for new users?

stevennoble
Explorer

When ever I create a new user I'd like to have some default rules in there search/local/ui-prefs.conf file. Is there a template which is copied for new users?

Tags (2)
1 Solution

jtrucks
Splunk Employee
Splunk Employee

You can create this file in $SPLUNK_HOME/etc/system/local if you want to force defaults for all users. Individuals accounts can, of course, have different options, as well.

--
Jesse Trucks
Minister of Magic

View solution in original post

dmaislin_splunk
Splunk Employee
Splunk Employee

I would setup Active Directory or LDAP authentication:

http://docs.splunk.com/Documentation/Splunk/6.0/Security/SetupuserauthenticationwithLDAP

Then I would create all the groups in AD and create roles in Splunk. Then you can easily manage the default user behavior in the Splunk roles.

I would then create an app and put that as their default app as well. Finally, you don't just have to put the ui-prefs.conf in system/local, you can put it in each [appname]/default or [appname]/local.

0 Karma

jtrucks
Splunk Employee
Splunk Employee

You can create this file in $SPLUNK_HOME/etc/system/local if you want to force defaults for all users. Individuals accounts can, of course, have different options, as well.

--
Jesse Trucks
Minister of Magic
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...