User Manual

 


Change Splunk Web preferences

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.

Change Splunk Web preferences

Use the Preferences panel to configure Splunk Web's default search properties and general appearance and behavior. The Preferences panel is a dialog box that opens when you click the Preferences link in the upper righthand corner of Splunk Web. Access the link on any of the dashboard pages.

The Preferences panel has two tabbed options: Search and General.


Change default settings in search preferences

Use the Search preferences tab to change:

Change default time range

To set the default time range for search, select one of the following options:

You can always change the time range at search time from the dashboard.

Change maximum search results

The maximum search results is the maximum number of events Splunk will return when you search. By default, this limit is 50k for 64-bit systems and 10k for 32-bit systems. Increasing or decreasing this number will affect Splunk's search speed.

Note: Increasing this number raises the maximum per-search memory cost and can negatively impact your Splunk server's performance.

Change segment selection

This setting affects how the browser interacts with Splunk and may speed up the display of search results. Splunk Web's segmentation setting is not related to indexing segmentation.

You can set segment selection to:

Change default settings in general preferences

Use the General preferences tab to define:

Change default theme

Splunk Web is defined with HTML, CSS, Javascript, and XSL. You can customize a theme with CSS files to override the default styles for font, color, and images. If you want to customize Splunk Web's appearance, refer to the Developer manual. You can also watch this Splunk developer video about it.

Change click behavior

You can click on sections of your search results to add or replace terms in your search. "Click behavior" configures either ctrl or ctrl-click to add and replace terms when narrowing your search.

This documentation applies to the following versions of Splunk: 3.3 , 3.3.1 , 3.3.2 , 3.3.3 , 3.3.4 , 3.4 , 3.4.1 , 3.4.2 , 3.4.3 , 3.4.5 , 3.4.6 , 3.4.8 , 3.4.9 , 3.4.10 , 3.4.11 , 3.4.12 , 3.4.13 , 3.4.14 View the Article History for its revisions.


You must be logged into splunk.com in order to post comments. Log in now.

Was this documentation topic helpful?

If you'd like to hear back from us, please provide your email address:

We'd love to hear what you think about this topic or the documentation as a whole. Feedback you enter here will be delivered to the documentation team.