Security

Why is my default app not loading when Users login?

Kozanic
Path Finder

I have tried many things and googled, but unable to find a solution to this issue.

I have an environment that I have inherited from someone else, who has now left.

Situation is I want users to have a particular app load up as their default when logging into Splunk, but it always loads up Search App instead - no matter what I try.

My attempts so far have included:

  • Editing user-prefs.conf (/opt/splunk/etc/apps/user-prefs/local) with the below: [role_RoleName] default_namespace = AppName
  • Setting Default App via the GUI
  • I have checked all roles to ensure that Search is not set as a default app for any roles (in case of inheritance overwriting)

Not sure is there is anything else I can check / modify to get this working?

0 Karma
1 Solution

Kozanic
Path Finder

OK - so figured out the issue.

Within my own account I had Search set as the default app - have removed this and is now working.

View solution in original post

0 Karma

Kozanic
Path Finder

OK - so figured out the issue.

Within my own account I had Search set as the default app - have removed this and is now working.

0 Karma

Kozanic
Path Finder

I have since discovered that the "Users" are actually getting the App as their default landing page - seems is only me.

Have double checked permissions on the APP - all good there.

My account has multiple roles associated to it - one of them admin - not sure if that has anything to do with why I'm not getting the default APP?

I even tried setting Search App to not be visible - but that just produced an error page and locked me out of the system temporarily.

Issue is less impacting now that I know it is only me affected - but still curious to understand why this is happening.

0 Karma

lguinn2
Legend

Check the permissions for the app. Users must have at least read permissions in order to see/use an app.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...