Splunk tweaks

Set the default search time period.
$SPLUNK_HOME/etc/system/local/ui-prefs.conf file includes:

[search]
 dispatch.earliest_time = -15m
 dispatch.latest_time = now

----------------------