Splunk Search

I need to set 24hours default search intervals for user role

jayakumar89
Explorer

We have 3 custom roles (user, power user and admin) and i would like to set 24hours as default search interval or block all time option only for all users who are mapped to user role. Any help would be appreciated.

TIA
Jay

Tags (1)
0 Karma
1 Solution

adonio
Ultra Champion

Hi jayakumar89,
using the setting highlighted in the attached picture you can prevent from users under a certain role from searching past a certain time
you can also set ui-pref.conf to set default search time. some related answers here:
https://answers.splunk.com/answers/106136/how-to-set-the-default-search-time-in-splunk-6.html
https://answers.splunk.com/answers/105781/splunk-6-0-default-time-in-time-picker.html
more on ui-pref.conf here:
https://docs.splunk.com/Documentation/Splunk/6.5.2/Admin/Ui-prefsconf![alt text]1

alt text

View solution in original post

adonio
Ultra Champion

Hi jayakumar89,
using the setting highlighted in the attached picture you can prevent from users under a certain role from searching past a certain time
you can also set ui-pref.conf to set default search time. some related answers here:
https://answers.splunk.com/answers/106136/how-to-set-the-default-search-time-in-splunk-6.html
https://answers.splunk.com/answers/105781/splunk-6-0-default-time-in-time-picker.html
more on ui-pref.conf here:
https://docs.splunk.com/Documentation/Splunk/6.5.2/Admin/Ui-prefsconf![alt text]1

alt text

jayakumar89
Explorer

Thanks for the info. Is it possible to make users does not have All time option at all ?

0 Karma

woodcock
Esteemed Legend

Yes, you create a .../local/times.conf that has this content:

[all_time]
disabled = 1
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...