Splunk Search

Force users to always use "optional" field with built-in SPL command

brinley
Path Finder

I'd like to ensure that all users on my search head are forced to include a specific field (along with a specific value) whenever they are employing a certain command in an SPL query. The particular field I want them to always use is listed as an "optional" argument in the command's SPL docs--basically, I want to make this field required and prevent users from giving this field any value that is different from the one I specify.

For example: I'd like to modify head so that a user always has to use limit=50 whenever they invoke this command. Currently, limit is listed as an "optional" head argument--I want to make it required AND prevent users from giving limit any value besides 50.

I'm thinking there might be something I can add to commands.conf to achieve this but am not sure. Any suggestions?

Get Updates on the Splunk Community!

Announcing General Availability of Splunk Incident Intelligence!

Digital transformation is real! Across industries, companies big and small are going through rapid digital ...

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...