Splunk Search

I need to set 24hours default search intervals for user role

jayakumar89
Explorer

We have 3 custom roles (user, power user and admin) and i would like to set 24hours as default search interval or block all time option only for all users who are mapped to user role. Any help would be appreciated.

TIA
Jay

Tags (1)
0 Karma
1 Solution

adonio
Ultra Champion

Hi jayakumar89,
using the setting highlighted in the attached picture you can prevent from users under a certain role from searching past a certain time
you can also set ui-pref.conf to set default search time. some related answers here:
https://answers.splunk.com/answers/106136/how-to-set-the-default-search-time-in-splunk-6.html
https://answers.splunk.com/answers/105781/splunk-6-0-default-time-in-time-picker.html
more on ui-pref.conf here:
https://docs.splunk.com/Documentation/Splunk/6.5.2/Admin/Ui-prefsconf![alt text]1

alt text

View solution in original post

adonio
Ultra Champion

Hi jayakumar89,
using the setting highlighted in the attached picture you can prevent from users under a certain role from searching past a certain time
you can also set ui-pref.conf to set default search time. some related answers here:
https://answers.splunk.com/answers/106136/how-to-set-the-default-search-time-in-splunk-6.html
https://answers.splunk.com/answers/105781/splunk-6-0-default-time-in-time-picker.html
more on ui-pref.conf here:
https://docs.splunk.com/Documentation/Splunk/6.5.2/Admin/Ui-prefsconf![alt text]1

alt text

jayakumar89
Explorer

Thanks for the info. Is it possible to make users does not have All time option at all ?

0 Karma

woodcock
Esteemed Legend

Yes, you create a .../local/times.conf that has this content:

[all_time]
disabled = 1
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Thanks for the Memories! Splunk University, .conf25, and our Community

Thank you to everyone in the Splunk Community who joined us for .conf25, which kicked off with our iconic ...