Splunk Enterprise

"ui-prefs.conf" no more working from Version 7 to Version 8.2.12

verbal_666
Builder

Hello.
Upgrading from Version 7 to Version 8.2.12,
we noticed that the "ui-prefs.conf" is not working anymore.

Inside the /etc/user/app/local/ui-prefs.conf we have every user customization, now they are totally skipped.
Also the admin, can't change his default view type (ex. "fast/smart/verbose").

Is there a reason?
And is there a way to restore this feature?

Thanks.

0 Karma

verbal_666
Builder

FACT: ui-prefs is broken! ☹️

verbal_666
Builder

For some strange reason, in version 8.2.12 "ui-prefs" is not managed anymore by default.
This is not much documented, as it should!!! 😠

To get rid of it, and get back with original ui management, we could try to edit a "local/web-features.conf"

 

 

[feature:ui_prefs_optimizations]
optimize_ui_prefs_performance = false

 

 

But it's like playing the lottery, sometimes works, others not, with new apps not at all 🤦‍♂️

 

I don't think this is a good idea changing the bahaviour of UI so drastically.
Above all, it's not documented anywhere, and we had to go around the web to understand it!!!

🤔🤔🤔🤔🤔

0 Karma

verbal_666
Builder

They did a real great mess, after 7.0, and some 8.x release
Also with false in optimize_ui_prefs_performance, i'm now on 8.2.12 version,

1) optimize_ui_prefs_performance to true destroyes all old users customization on search tab

... also with optimize_ui_prefs_performance to false,

2) new ui-prefs.conf are not created anymore, only old ui-prefs are managed
3) also etc/users/launcher/local/ui-prefs.conf to remove "Explore Splunk Enterprise" banner has gone away!
4) users can't change Alerts/Reports/Dashboards object view modality (general/owner/app), since it's defaulted and reverted back to "All" next time you load the page!!!

verbal_666_0-1701655583364.png

 

 

5) seems ui-prefs is right managed only in "app/search/search|alerts|reports|dashboards" (default search App)

This is really a great mess!!!

We have had many users complain about this poor UI management!!!

 

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...