Splunk Search

How to remove some extra options from a custom time picker?

AKG1_old1
Builder

Hello,

I am looking to remove some extra options from Time picker. I have disabled them through GUI (User Interface >> Time ranges).

When I check using CLI it shows these are disabled but those options are still present. (I have checked by removing brower caching)

PS: I don't have times.conf for App specific. My app using default one.

Please advice if I am missing something.

alt text
alt text
alt text
Thanks

0 Karma
1 Solution

AKG1_old1
Builder

Not sure why disable doesn't work but removing entries from below file worked for me.
splunk/etc/system/default/times.conf

View solution in original post

0 Karma

AKG1_old1
Builder

Not sure why disable doesn't work but removing entries from below file worked for me.
splunk/etc/system/default/times.conf

0 Karma

p_gurav
Champion

You can try this option of creating CSS:
https://simonduff.net/splunk_restrict_time_range_picker/

AKG1_old1
Builder

Thanks, I think it's for older Splunk versions. I have latest Splunk v7.x.

Like
Old version
div[id^='realtime_view']

New Version
div[data-test-panel-id^='real']

Not sure about sytax for individal item in newer version

Old Version
a[data-earliest="@d"][data-latest="now"]

New
??

0 Karma

AKG1_old1
Builder

Thanks, Actually I have removed the entries from and it worked.

splunk/etc/system/default/times.conf

0 Karma

deepashri_123
Motivator

Hey @agoyal,

Refer this answer:
https://answers.splunk.com/answers/222650/limit-choices-in-default-timepicker.html

Let me know if this helps!!

AKG1_old1
Builder

Thanks. it's useful but doen't sovle my problem.

The other post is to hide the full sections like it I want to remove full section out of Presents, Relative, Date range etc. My requirement is to remove some options from Presents section. (Attached screenshot in main question)

Ex. this code worked for remove full real-time section.
div[data-test-panel-id^='real'] {
display: none !important;
}

0 Karma

AKG1_old1
Builder

Thanks, Actually I have removed the entries from and it worked.

splunk/etc/system/default/times.conf

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...