Dashboards & Visualizations

How to enable only current few(N) days in datetimerange accordion in datetimerange picker

basilarockiaedw
Path Finder

In My Splunk Dashboard we have a requirement to disable past dates other than current date in the datettimerange picker.i know it is possible to hide and show some accordion in datetimerage picker. But have no idea on how to disable/enable certain dates.
any help on this is highly appreciated.

0 Karma
1 Solution

woodcock
Esteemed Legend

You must create this custom file:

$SPLUNK_HOME/etc/apps/YourAppHere/local/times.conf

You can copy the full one from here and pare it down:

$SPLUNK_HOME/etc/system/default/times.conf

View solution in original post

0 Karma

woodcock
Esteemed Legend

You must create this custom file:

$SPLUNK_HOME/etc/apps/YourAppHere/local/times.conf

You can copy the full one from here and pare it down:

$SPLUNK_HOME/etc/system/default/times.conf
0 Karma

basilarockiaedw
Path Finder

Thanks for the response!. I don't find an option to disable current day or previous day in the date menu in the times.conf which you have asked to modify though it has the ability to add or remote certain category of timepicker.

0 Karma

woodcock
Esteemed Legend
0 Karma
Get Updates on the Splunk Community!

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Dashboard Challenge and Watch the .conf24 Global Broadcast!

The Splunk Community Dashboard Challenge is still happening, and it's not too late to enter for the week of ...