Splunk Search

Force users to always use "optional" field with built-in SPL command

brinley
Path Finder

I'd like to ensure that all users on my search head are forced to include a specific field (along with a specific value) whenever they are employing a certain command in an SPL query. The particular field I want them to always use is listed as an "optional" argument in the command's SPL docs--basically, I want to make this field required and prevent users from giving this field any value that is different from the one I specify.

For example: I'd like to modify head so that a user always has to use limit=50 whenever they invoke this command. Currently, limit is listed as an "optional" head argument--I want to make it required AND prevent users from giving limit any value besides 50.

I'm thinking there might be something I can add to commands.conf to achieve this but am not sure. Any suggestions?

Get Updates on the Splunk Community!

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...