Splunk Search

How to remove some extra options from a custom time picker?

AKG1_old1
Builder

Hello,

I am looking to remove some extra options from Time picker. I have disabled them through GUI (User Interface >> Time ranges).

When I check using CLI it shows these are disabled but those options are still present. (I have checked by removing brower caching)

PS: I don't have times.conf for App specific. My app using default one.

Please advice if I am missing something.

alt text
alt text
alt text
Thanks

0 Karma
1 Solution

AKG1_old1
Builder

Not sure why disable doesn't work but removing entries from below file worked for me.
splunk/etc/system/default/times.conf

View solution in original post

0 Karma

AKG1_old1
Builder

Not sure why disable doesn't work but removing entries from below file worked for me.
splunk/etc/system/default/times.conf

0 Karma

p_gurav
Champion

You can try this option of creating CSS:
https://simonduff.net/splunk_restrict_time_range_picker/

AKG1_old1
Builder

Thanks, I think it's for older Splunk versions. I have latest Splunk v7.x.

Like
Old version
div[id^='realtime_view']

New Version
div[data-test-panel-id^='real']

Not sure about sytax for individal item in newer version

Old Version
a[data-earliest="@d"][data-latest="now"]

New
??

0 Karma

AKG1_old1
Builder

Thanks, Actually I have removed the entries from and it worked.

splunk/etc/system/default/times.conf

0 Karma

deepashri_123
Motivator

Hey @agoyal,

Refer this answer:
https://answers.splunk.com/answers/222650/limit-choices-in-default-timepicker.html

Let me know if this helps!!

AKG1_old1
Builder

Thanks. it's useful but doen't sovle my problem.

The other post is to hide the full sections like it I want to remove full section out of Presents, Relative, Date range etc. My requirement is to remove some options from Presents section. (Attached screenshot in main question)

Ex. this code worked for remove full real-time section.
div[data-test-panel-id^='real'] {
display: none !important;
}

0 Karma

AKG1_old1
Builder

Thanks, Actually I have removed the entries from and it worked.

splunk/etc/system/default/times.conf

0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

March Community Office Hours Security Series Uncovered!

Hello Splunk Community! In March, Splunk Community Office Hours spotlighted our fabulous Splunk Threat ...

Stay Connected: Your Guide to April Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars in April. This post ...