Splunk Search

How to enable Search Assistant for all users on a Search Head Cluster?

JDukeSplunk
Builder

I would like to enable to search assistant on my Search Head Cluster. The documentation recommends an edit to the file user-prefs.conf.spec.in. (Is this a bad idea?)

Described here:
https://docs.splunk.com/Documentation/Splunk/6.5.0/Search/Usingthesearchassistant#Change_the_default...

However, this file (user-prefs.conf.spec.in) does not exist in ../local or ../default.

splunk@atlitpspsh2:/opt/splunk/etc/apps/search/local> ls -lha
total 280K
drwx------  3 splunk splunk 4.0K Jan 26 15:14 .
drwxr-xr-x 22 splunk splunk 4.0K Dec 19 11:24 ..
-rw-------  1 splunk splunk  657 Sep 29 15:26 collections.conf
drwx------  4 splunk splunk 4.0K Mar  7  2016 data
-rw-------  1 splunk splunk  105 Jul 27  2016 datamodels.conf
-rw-------  1 splunk splunk  138 Aug 12 16:40 eventtypes.conf
-rw-------  1 splunk splunk    0 Sep 15  2015 inputs.conf
-rw-------  1 splunk splunk 8.5K Dec 15 10:50 props.conf
-rw-------  1 splunk splunk 167K Jan 26 15:14 savedsearches.conf
-rw-------  1 splunk splunk  11K Aug 19 11:34 tags.conf
-rw-------  1 splunk splunk  901 Sep 30 10:21 transforms.conf
-rw-------  1 splunk splunk  49K Oct 22  2015 viewstates.conf
-rw-------  1 splunk splunk    0 Dec 16 13:57 workflow_actions.conf

Can one simply find the spec file for this and add it to the search heads one at a time? If so, should it keep that name, or be renamed to user-prefs.conf?

-Thanks

0 Karma
1 Solution

arkadyz1
Builder

I believe you should copy user-prefs.conf.spec from etc/system/README as etc/<yourapp>/local/user-prefs.conf and edit that one. So you do change the name to the usual user-prefs.conf. The file name user-prefs.conf.spec.in in the docs seems to be a typo.

View solution in original post

0 Karma

arkadyz1
Builder

I believe you should copy user-prefs.conf.spec from etc/system/README as etc/<yourapp>/local/user-prefs.conf and edit that one. So you do change the name to the usual user-prefs.conf. The file name user-prefs.conf.spec.in in the docs seems to be a typo.

0 Karma

JDukeSplunk
Builder

I'll get back to you as to whether or not this worked.

0 Karma
Get Updates on the Splunk Community!

New Case Study Shows the Value of Partnering with Splunk Academic Alliance

The University of Nevada, Las Vegas (UNLV) is another premier research institution helping to shape the next ...

How to Monitor Google Kubernetes Engine (GKE)

We’ve looked at how to integrate Kubernetes environments with Splunk Observability Cloud, but what about ...

Index This | How can you make 45 using only 4?

October 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...