Splunk Search

Warning/Error Banner messages

rmorlen
Splunk Employee
Splunk Employee

I would like to suppress all messages in the search app. It would be nice to be able to suppress then by role so that Admins see the messages but Users don't.

Any suggestions on how to do this?

Currently we are using Splunk 4.2.5.

Tags (2)

vsingla1
Communicator

It will be a great feature if this can be setup by role basis. Non-admin users do not need to see all those errors. It only creates unnecessary email chain and that too a big one. 🙂

0 Karma

baerts
Path Finder

Is there anything new in 6.2.2 on how to control these messages in a better way?
I noticed somewhere in a script under templates/lib.html a reference to a variable DISABLE_MESSENGER but no reference as how to use this.

0 Karma

lguinn2
Legend

AFAIK, there is no way to do this by role. You can, however, edit the views in the search app so that no one gets the messages. You can also filter the messages so that not all messages appear; this might be some improvement, even if it isn't perfect.

Look at the Messaging Module reference for more info.

0 Karma

lguinn2
Legend

Yes, it should be in 5-6 files (or more)! The flashtimeline view is the familiar search view that shows search results, the search bar, etc etc.

0 Karma

rmorlen
Splunk Employee
Splunk Employee

I looked at that information but couldn't figure out where in the search app views the banner is displayed. I see the Message module referenced in about 5-6 files.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...