This can also be set on a per-user basis in the etc/users/
TimeRangePicker_0_1_0.default = Last 15 minutes
TimeRangePicker_0_1_0.default = Last 4 hours
You need to change this in all of the search views. For Splunk 4.3, there are two default search views in the Search app.
Look under Manager » User interface » Views and choose the App Context "search".
You should see a view named "flashtimeline" and a view named "dashboard_live". (BTW, dashboard_live is the name of the Summary view.)
Edit each view by clicking on its name. Look for the two lines
<param name="selected">All time</param>
All time to the default time range of your choice. Spell it exactly as it appears in the time range picker drop-down. For example
<param name="selected">Last 60 minutes</param>
Save your edits.
When you have done this for both views, you will have altered the defaults. If you have other, custom search views, you may need to edit them as well. And you may need to repeat this when you install updates to Splunk. Fortunately, it is easy to do.