Splunk Search

Search assistant help text

bmgilmore
Path Finder

Is there a supported way to edit/expand the "How to Search" text in the search bar assistant? Let me know, thanks,

Tags (1)
0 Karma

ChrisG
Splunk Employee
Splunk Employee

This text is contained in searchbnf.conf. There is a searchbnf.conf in $SPLUNK_HOME/etc/system/default/. You should not modify it. If your application has its own custom python search commands, your application can include its own searchbnf.conf to describe the commands to the search assistant.

0 Karma

ChrisG
Splunk Employee
Splunk Employee

Sorry for the delayed follow-up, I was away for a few days. The strings you are looking for are contained in the messages.pot files in $SPLUNK_HOME/lib/python2.7/site-packages/splunk/appserver/mrsparkle/locale.

HOWEVER: it is not recommended that you modify this file. It will be overwritten whenever you upgrade, and modifying default Splunk files is not a good practice as a general rule. It can make it difficult for customer support to help you and can have unanticipated effects in your installation.

0 Karma

bmgilmore
Path Finder

Thanks, that is good to know, I am really looking for the following text:

How to Search
Step 1: Retrieve Events The simplest searches return events that match terms you type into the search bar:

etc...

I dont see this in searchbnf?

Let me know, thanks again!

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...