Splunk Search

How to remove some extra options from a custom time picker?

AKG1_old1
Builder

Hello,

I am looking to remove some extra options from Time picker. I have disabled them through GUI (User Interface >> Time ranges).

When I check using CLI it shows these are disabled but those options are still present. (I have checked by removing brower caching)

PS: I don't have times.conf for App specific. My app using default one.

Please advice if I am missing something.

alt text
alt text
alt text
Thanks

0 Karma
1 Solution

AKG1_old1
Builder

Not sure why disable doesn't work but removing entries from below file worked for me.
splunk/etc/system/default/times.conf

View solution in original post

0 Karma

AKG1_old1
Builder

Not sure why disable doesn't work but removing entries from below file worked for me.
splunk/etc/system/default/times.conf

0 Karma

p_gurav
Champion

You can try this option of creating CSS:
https://simonduff.net/splunk_restrict_time_range_picker/

AKG1_old1
Builder

Thanks, I think it's for older Splunk versions. I have latest Splunk v7.x.

Like
Old version
div[id^='realtime_view']

New Version
div[data-test-panel-id^='real']

Not sure about sytax for individal item in newer version

Old Version
a[data-earliest="@d"][data-latest="now"]

New
??

0 Karma

AKG1_old1
Builder

Thanks, Actually I have removed the entries from and it worked.

splunk/etc/system/default/times.conf

0 Karma

deepashri_123
Motivator

Hey @agoyal,

Refer this answer:
https://answers.splunk.com/answers/222650/limit-choices-in-default-timepicker.html

Let me know if this helps!!

AKG1_old1
Builder

Thanks. it's useful but doen't sovle my problem.

The other post is to hide the full sections like it I want to remove full section out of Presents, Relative, Date range etc. My requirement is to remove some options from Presents section. (Attached screenshot in main question)

Ex. this code worked for remove full real-time section.
div[data-test-panel-id^='real'] {
display: none !important;
}

0 Karma

AKG1_old1
Builder

Thanks, Actually I have removed the entries from and it worked.

splunk/etc/system/default/times.conf

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...