Splunk® Enterprise

Admin Manual

Display global banner

Splunk Enterprise lets you display a global banner that remains visible to all users on all UI pages across the product. The global banner feature gives organizations with strict security concerns the ability to display a site classification message that is required to run Splunk software in some environments. For example, you can display a global banner that tells users they are using a secure or classified site.

While the primary use case for the global banner is the persistent display of a site classification message, you can use it to display any type of notification that requires a persistent, highly visible message. For example, you can use the global banner to notify users about:

  • New features
  • Software version upgrades
  • Scheduled maintenance or downtime
  • Data outages

Splunk Web bulletin messages are suitable for most in-product notifications that do not require a persistent global message. For more information on bulletin messages, see Customize Splunk Web messages.

Splunk Enterprise supports the display of a single global banner only. The global banner does not appear on the Splunk Enterprise login page and users cannot dismiss the banner inside the product.

Customize the global banner

You can enable and customize the global banner using Splunk Web, REST, or configuration files.

To customize the global banner a role must have the edit_global_banner capability. This capability is provided to admin and sc_admin roles by default.

Customize global banner using Splunk Web

  1. In Splunk Web, click Settings > Server Settings > Global Banner.
  2. Toggle the Banner Visibility switch to On.
  3. Select a background color for your global banner.
  4. Enter your message text.
  5. (optional) Specify a URL to generate a hyperlink to additional information, such as relevant best practices documentation.
  6. Enter text for the hyperlink. For example, "Learn about best practices".
    Your customized global banner now appears on all UI pages in Splunk Enterprise.
    The image shows an example global banner across the top of the Customize Global Banner Page in Splunk Web. The global banner states this is a "Secure Site" and provides a hyperlink to best practices documentation.

Deploy global banner in a search head cluster

In a search head cluster environment, some sections of the Settings menu in Splunk Web are hidden by default. To deploy the global banner using Splunk Web in a search head cluster, you must first show the full Settings menu, as follows:

  1. On any cluster member, in Splunk Web, click Settings > Show All Settings > Show.
    The full Settings menu now appears in Splunk Web.
  2. Click Server settings > Global banner.
  3. Customize the global banner as shown in the preceding section Customize global banner using Splunk Web.
  4. Click Save.
    The search head cluster automatically replicates the global banner configuration to each cluster member and the global banner now appears in Splunk Web on each search head.

Customize global banner using REST

To customize the global banner using REST, send a POST request to the following endpoint:


For endpoint details, see data/ui/global-banner in the REST API Reference Manual.

Customize global banner using configuration files

You can customize the global banner by specifying settings in $SPLUNK_HOME/etc/system/local/global-banner.conf.

For detailed information on global-banner.conf settings, see global-banner.conf.

Last modified on 01 August, 2023
Customize Splunk Web messages   About configuration files

This documentation applies to the following versions of Splunk® Enterprise: 8.1.0, 8.1.1, 8.1.2, 8.1.3, 8.1.4, 8.1.5, 8.1.6, 8.1.7, 8.1.8, 8.1.9, 8.1.10, 8.1.11, 8.1.12, 8.1.13, 8.1.14, 8.2.0, 8.2.1, 8.2.2, 8.2.3, 8.2.4, 8.2.5, 8.2.6, 8.2.7, 8.2.8, 8.2.9, 8.2.10, 8.2.11, 8.2.12, 9.0.0, 9.0.1, 9.0.2, 9.0.3, 9.0.4, 9.0.5, 9.0.6, 9.0.7, 9.0.8, 9.0.9, 9.1.0, 9.1.1, 9.1.2, 9.1.3, 9.1.4, 9.2.0, 9.2.1

Was this topic useful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters