Splunk Search

How to enable Search Assistant for all users on a Search Head Cluster?

JDukeSplunk
Builder

I would like to enable to search assistant on my Search Head Cluster. The documentation recommends an edit to the file user-prefs.conf.spec.in. (Is this a bad idea?)

Described here:
https://docs.splunk.com/Documentation/Splunk/6.5.0/Search/Usingthesearchassistant#Change_the_default...

However, this file (user-prefs.conf.spec.in) does not exist in ../local or ../default.

splunk@atlitpspsh2:/opt/splunk/etc/apps/search/local> ls -lha
total 280K
drwx------  3 splunk splunk 4.0K Jan 26 15:14 .
drwxr-xr-x 22 splunk splunk 4.0K Dec 19 11:24 ..
-rw-------  1 splunk splunk  657 Sep 29 15:26 collections.conf
drwx------  4 splunk splunk 4.0K Mar  7  2016 data
-rw-------  1 splunk splunk  105 Jul 27  2016 datamodels.conf
-rw-------  1 splunk splunk  138 Aug 12 16:40 eventtypes.conf
-rw-------  1 splunk splunk    0 Sep 15  2015 inputs.conf
-rw-------  1 splunk splunk 8.5K Dec 15 10:50 props.conf
-rw-------  1 splunk splunk 167K Jan 26 15:14 savedsearches.conf
-rw-------  1 splunk splunk  11K Aug 19 11:34 tags.conf
-rw-------  1 splunk splunk  901 Sep 30 10:21 transforms.conf
-rw-------  1 splunk splunk  49K Oct 22  2015 viewstates.conf
-rw-------  1 splunk splunk    0 Dec 16 13:57 workflow_actions.conf

Can one simply find the spec file for this and add it to the search heads one at a time? If so, should it keep that name, or be renamed to user-prefs.conf?

-Thanks

0 Karma
1 Solution

arkadyz1
Builder

I believe you should copy user-prefs.conf.spec from etc/system/README as etc/<yourapp>/local/user-prefs.conf and edit that one. So you do change the name to the usual user-prefs.conf. The file name user-prefs.conf.spec.in in the docs seems to be a typo.

View solution in original post

0 Karma

arkadyz1
Builder

I believe you should copy user-prefs.conf.spec from etc/system/README as etc/<yourapp>/local/user-prefs.conf and edit that one. So you do change the name to the usual user-prefs.conf. The file name user-prefs.conf.spec.in in the docs seems to be a typo.

0 Karma

JDukeSplunk
Builder

I'll get back to you as to whether or not this worked.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...