Splunk Search

How to remove some extra options from a custom time picker?

AKG1_old1
Builder

Hello,

I am looking to remove some extra options from Time picker. I have disabled them through GUI (User Interface >> Time ranges).

When I check using CLI it shows these are disabled but those options are still present. (I have checked by removing brower caching)

PS: I don't have times.conf for App specific. My app using default one.

Please advice if I am missing something.

alt text
alt text
alt text
Thanks

0 Karma
1 Solution

AKG1_old1
Builder

Not sure why disable doesn't work but removing entries from below file worked for me.
splunk/etc/system/default/times.conf

View solution in original post

0 Karma

AKG1_old1
Builder

Not sure why disable doesn't work but removing entries from below file worked for me.
splunk/etc/system/default/times.conf

0 Karma

p_gurav
Champion

You can try this option of creating CSS:
https://simonduff.net/splunk_restrict_time_range_picker/

AKG1_old1
Builder

Thanks, I think it's for older Splunk versions. I have latest Splunk v7.x.

Like
Old version
div[id^='realtime_view']

New Version
div[data-test-panel-id^='real']

Not sure about sytax for individal item in newer version

Old Version
a[data-earliest="@d"][data-latest="now"]

New
??

0 Karma

AKG1_old1
Builder

Thanks, Actually I have removed the entries from and it worked.

splunk/etc/system/default/times.conf

0 Karma

deepashri_123
Motivator

Hey @agoyal,

Refer this answer:
https://answers.splunk.com/answers/222650/limit-choices-in-default-timepicker.html

Let me know if this helps!!

AKG1_old1
Builder

Thanks. it's useful but doen't sovle my problem.

The other post is to hide the full sections like it I want to remove full section out of Presents, Relative, Date range etc. My requirement is to remove some options from Presents section. (Attached screenshot in main question)

Ex. this code worked for remove full real-time section.
div[data-test-panel-id^='real'] {
display: none !important;
}

0 Karma

AKG1_old1
Builder

Thanks, Actually I have removed the entries from and it worked.

splunk/etc/system/default/times.conf

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...