From Splunk Wiki

Jump to: navigation, search

< Back to Best Practices

How to disable Splunk dashboards

Splunk ships with 3 dashboards: Main, Admin and Getting Started. In some situations, you may want to remove/disable these dashboards. This involves a simple edit to the $SPLUNK_HOME/etc/system/local/prefs.conf file.

Add the following set of lines to the top of your $SPLUNK_HOME/etc/system/local/prefs.conf:

dashboardset_getting_started = SPLUNK-DELETED-DASHBOARD
dashboardset_admin = SPLUNK-DELETED-DASHBOARD
dashboardset_main = SPLUNK-DELETED-DASHBOARD
dashboard_activeset = test
dashboardset_test = null
dashboard_intro_getting_started =

In the example provided above, replace 'test' with the name of the custom/default dashboard you want the user to be assigned at first login.

Once the configuration change has been saved, restart Splunk. Any new users will now be assigned the above dashboard settings.

NOTE: Keep in mind that the dashboards may still be altered by your users. If a user happens to create any dashboard with the name admin, main or Getting Started, they will be presented with a blank dashboard that they may add saved searches to.

Personal tools
Hot Wiki Topics

About Splunk >
  • Search and navigate IT data from applications, servers and network devices in real-time.
  • Download Splunk