Splunk® Enterprise

Admin Manual

Acrobat logo Download manual as PDF

Acrobat logo Download topic as PDF

Display global banner

Splunk Enterprise lets you display a global banner that remains visible to all users on all UI pages across the product. The global banner feature gives organizations with strict security concerns the ability to display a site classification message that is required to run Splunk software in some environments. For example, you can display a global banner that tells users they are using a secure or classified site.

While the primary use case for the global banner is the persistent display of a site classification message, you can use it to display any type of notification that requires a persistent, highly visible message. For example, you can use the global banner to notify users about:

  • New features
  • Software version upgrades
  • Scheduled maintenance or downtime
  • Data outages

Splunk Web bulletin messages are suitable for most in-product notifications that do not require a persistent global message. For more information on bulletin messages, see Customize Splunk Web messages.

Splunk Enterprise supports the display of a single global banner only. The global banner does not appear on the Splunk Enterprise login page and users cannot dismiss the banner inside the product.

Customize the global banner

You can enable and customize the global banner using Splunk Web, REST, or configuration files.

To customize the global banner a role must have the edit_global_banner capability. This capability is provided to admin and sc_admin roles by default.

Customize global banner using Splunk Web

  1. In Splunk Web, click Settings > Server Settings > Global Banner.
  2. Toggle the Banner Visibility switch to On.
  3. Select a background color for your global banner.
  4. Enter your message text.
  5. (optional) Specify a URL to generate a hyperlink to additional information, such as relevant best practices documentation.
  6. Enter text for the hyperlink. For example, "Learn about best practices".
    Your customized global banner now appears on all UI pages in Splunk Enterprise.
    The image shows an example global banner across the top of the Customize Global Banner Page in Splunk Web. The global banner states this is a "Secure Site" and provides a hyperlink to best practices documentation.

Customize global banner using REST

To customize the global banner using REST, send a POST request to the following endpoint:

data/ui/global-banner

For endpoint details, see data/ui/global-banner in the REST API Reference Manual.

Customize global banner using configuration files

You can customize the global banner by specifying settings in $SPLUNK_HOME/etc/system/local/global-banner.conf.

For detailed information on global-banner.conf settings, see global-banner.conf.

Last modified on 18 August, 2020
PREVIOUS
Customize Splunk Web messages
  NEXT
About configuration files

This documentation applies to the following versions of Splunk® Enterprise: 8.1.0


Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters