Splunk Enterprise

"ui-prefs.conf" no more working from Version 7 to Version 8.2.12

verbal_666
Builder

Hello.
Upgrading from Version 7 to Version 8.2.12,
we noticed that the "ui-prefs.conf" is not working anymore.

Inside the /etc/user/app/local/ui-prefs.conf we have every user customization, now they are totally skipped.
Also the admin, can't change his default view type (ex. "fast/smart/verbose").

Is there a reason?
And is there a way to restore this feature?

Thanks.

0 Karma

verbal_666
Builder

FACT: ui-prefs is broken! ☹️

verbal_666
Builder

For some strange reason, in version 8.2.12 "ui-prefs" is not managed anymore by default.
This is not much documented, as it should!!! 😠

To get rid of it, and get back with original ui management, we could try to edit a "local/web-features.conf"

 

 

[feature:ui_prefs_optimizations]
optimize_ui_prefs_performance = false

 

 

But it's like playing the lottery, sometimes works, others not, with new apps not at all 🤦‍♂️

 

I don't think this is a good idea changing the bahaviour of UI so drastically.
Above all, it's not documented anywhere, and we had to go around the web to understand it!!!

🤔🤔🤔🤔🤔

0 Karma

verbal_666
Builder

They did a real great mess, after 7.0, and some 8.x release
Also with false in optimize_ui_prefs_performance, i'm now on 8.2.12 version,

1) optimize_ui_prefs_performance to true destroyes all old users customization on search tab

... also with optimize_ui_prefs_performance to false,

2) new ui-prefs.conf are not created anymore, only old ui-prefs are managed
3) also etc/users/launcher/local/ui-prefs.conf to remove "Explore Splunk Enterprise" banner has gone away!
4) users can't change Alerts/Reports/Dashboards object view modality (general/owner/app), since it's defaulted and reverted back to "All" next time you load the page!!!

verbal_666_0-1701655583364.png

 

 

5) seems ui-prefs is right managed only in "app/search/search|alerts|reports|dashboards" (default search App)

This is really a great mess!!!

We have had many users complain about this poor UI management!!!

 

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...