Splunk Search

Warning/Error Banner messages

rmorlen
Splunk Employee
Splunk Employee

I would like to suppress all messages in the search app. It would be nice to be able to suppress then by role so that Admins see the messages but Users don't.

Any suggestions on how to do this?

Currently we are using Splunk 4.2.5.

Tags (2)

vsingla1
Communicator

It will be a great feature if this can be setup by role basis. Non-admin users do not need to see all those errors. It only creates unnecessary email chain and that too a big one. 🙂

0 Karma

baerts
Path Finder

Is there anything new in 6.2.2 on how to control these messages in a better way?
I noticed somewhere in a script under templates/lib.html a reference to a variable DISABLE_MESSENGER but no reference as how to use this.

0 Karma

lguinn2
Legend

AFAIK, there is no way to do this by role. You can, however, edit the views in the search app so that no one gets the messages. You can also filter the messages so that not all messages appear; this might be some improvement, even if it isn't perfect.

Look at the Messaging Module reference for more info.

0 Karma

lguinn2
Legend

Yes, it should be in 5-6 files (or more)! The flashtimeline view is the familiar search view that shows search results, the search bar, etc etc.

0 Karma

rmorlen
Splunk Employee
Splunk Employee

I looked at that information but couldn't figure out where in the search app views the banner is displayed. I see the Message module referenced in about 5-6 files.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...

Federated Search for Dynamic Data Self Storage Is Now Generally Available on Splunk ...

 Splunk is excited to announce the General Availability of Federated Search for Dynamic Data Self Storage ...

Index This | What has many keys but can’t unlock a door?

July 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...