Splunk Search

How to remove some extra options from a custom time picker?

AKG1_old1
Builder

Hello,

I am looking to remove some extra options from Time picker. I have disabled them through GUI (User Interface >> Time ranges).

When I check using CLI it shows these are disabled but those options are still present. (I have checked by removing brower caching)

PS: I don't have times.conf for App specific. My app using default one.

Please advice if I am missing something.

alt text
alt text
alt text
Thanks

0 Karma
1 Solution

AKG1_old1
Builder

Not sure why disable doesn't work but removing entries from below file worked for me.
splunk/etc/system/default/times.conf

View solution in original post

0 Karma

AKG1_old1
Builder

Not sure why disable doesn't work but removing entries from below file worked for me.
splunk/etc/system/default/times.conf

0 Karma

p_gurav
Champion

You can try this option of creating CSS:
https://simonduff.net/splunk_restrict_time_range_picker/

AKG1_old1
Builder

Thanks, I think it's for older Splunk versions. I have latest Splunk v7.x.

Like
Old version
div[id^='realtime_view']

New Version
div[data-test-panel-id^='real']

Not sure about sytax for individal item in newer version

Old Version
a[data-earliest="@d"][data-latest="now"]

New
??

0 Karma

AKG1_old1
Builder

Thanks, Actually I have removed the entries from and it worked.

splunk/etc/system/default/times.conf

0 Karma

deepashri_123
Motivator

Hey @agoyal,

Refer this answer:
https://answers.splunk.com/answers/222650/limit-choices-in-default-timepicker.html

Let me know if this helps!!

AKG1_old1
Builder

Thanks. it's useful but doen't sovle my problem.

The other post is to hide the full sections like it I want to remove full section out of Presents, Relative, Date range etc. My requirement is to remove some options from Presents section. (Attached screenshot in main question)

Ex. this code worked for remove full real-time section.
div[data-test-panel-id^='real'] {
display: none !important;
}

0 Karma

AKG1_old1
Builder

Thanks, Actually I have removed the entries from and it worked.

splunk/etc/system/default/times.conf

0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...