<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Possible bug with changing permission on source based field extraction in Security</title>
    <link>https://community.splunk.com/t5/Security/Possible-bug-with-changing-permission-on-source-based-field/m-p/485232#M11152</link>
    <description>&lt;P&gt;I have the same problem with 8.0.1. Would be interested to know if there is a solution.&lt;/P&gt;</description>
    <pubDate>Thu, 30 Apr 2020 08:59:09 GMT</pubDate>
    <dc:creator>kaurinko</dc:creator>
    <dc:date>2020-04-30T08:59:09Z</dc:date>
    <item>
      <title>Possible bug with changing permission on source based field extraction</title>
      <link>https://community.splunk.com/t5/Security/Possible-bug-with-changing-permission-on-source-based-field/m-p/485230#M11150</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I just ran into the issue that I couldn't change the permission of a source based field extraction via GUI on 7.3.1.&lt;/P&gt;
&lt;P&gt;This only happens for source based field extrations, sourcetype ones are not affected.&lt;/P&gt;
&lt;P&gt;Clicking on the "Permissions" Link in Sharing results in an error like this:&lt;/P&gt;
&lt;PRE&gt;&lt;CODE&gt;Splunk could not retrieve permissions for resource data/props/extractions [HTTP 404] &lt;A href="https://127.0.0.1:8089/servicesNS/kainiels/search/data/props/extractions/source%253A%253A%252Fvar%252Flog%252Fbar%20%3A%20EXTRACT-foo?safe_encoding=1" target="test_blank"&gt;https://127.0.0.1:8089/servicesNS/kainiels/search/data/props/extractions/source%253A%253A%252Fvar%252Flog%252Fbar%20%3A%20EXTRACT-foo?safe_encoding=1&lt;/A&gt;; [{'type': 'ERROR', 'text': 'Could not find object id=source%3A%3A/var/log/bar : EXTRACT-foo', 'code': None}]
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;Can someone confirm that issue, or is our installation maybe broken somehow? I didn't see this mentioned in the release notes of later versions...&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jun 2020 17:28:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Possible-bug-with-changing-permission-on-source-based-field/m-p/485230#M11150</guid>
      <dc:creator>knielsen</dc:creator>
      <dc:date>2020-06-07T17:28:46Z</dc:date>
    </item>
    <item>
      <title>Re: Possible bug with changing permission on source based field extraction</title>
      <link>https://community.splunk.com/t5/Security/Possible-bug-with-changing-permission-on-source-based-field/m-p/485231#M11151</link>
      <description>&lt;P&gt;I have the same problem with version 7.2.9.1.  It appears to me that this error occurs for any field extraction that contains a forward slash /.  Did happen to get any confirmation this is a bug?&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2020 13:11:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Possible-bug-with-changing-permission-on-source-based-field/m-p/485231#M11151</guid>
      <dc:creator>darius_diederic</dc:creator>
      <dc:date>2020-02-13T13:11:34Z</dc:date>
    </item>
    <item>
      <title>Re: Possible bug with changing permission on source based field extraction</title>
      <link>https://community.splunk.com/t5/Security/Possible-bug-with-changing-permission-on-source-based-field/m-p/485232#M11152</link>
      <description>&lt;P&gt;I have the same problem with 8.0.1. Would be interested to know if there is a solution.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2020 08:59:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Possible-bug-with-changing-permission-on-source-based-field/m-p/485232#M11152</guid>
      <dc:creator>kaurinko</dc:creator>
      <dc:date>2020-04-30T08:59:09Z</dc:date>
    </item>
    <item>
      <title>Re: Possible bug with changing permission on source based field extraction</title>
      <link>https://community.splunk.com/t5/Security/Possible-bug-with-changing-permission-on-source-based-field/m-p/485233#M11153</link>
      <description>&lt;P&gt;I can confirm, that this only happens for source based field extractions. Ones with sourcetype-based searches are not affected.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2020 09:04:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Possible-bug-with-changing-permission-on-source-based-field/m-p/485233#M11153</guid>
      <dc:creator>kaurinko</dc:creator>
      <dc:date>2020-04-30T09:04:00Z</dc:date>
    </item>
    <item>
      <title>Re: Possible bug with changing permission on source based field extraction</title>
      <link>https://community.splunk.com/t5/Security/Possible-bug-with-changing-permission-on-source-based-field/m-p/485234#M11154</link>
      <description>&lt;P&gt;I received word from developers this bug will be fixed on version 7.2.11, 7.3.6 and 8.0.4 with a release date of 05/12/2020.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2020 12:31:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Possible-bug-with-changing-permission-on-source-based-field/m-p/485234#M11154</guid>
      <dc:creator>darius_diederic</dc:creator>
      <dc:date>2020-04-30T12:31:30Z</dc:date>
    </item>
    <item>
      <title>Re: Possible bug with changing permission on source based field extraction</title>
      <link>https://community.splunk.com/t5/Security/Possible-bug-with-changing-permission-on-source-based-field/m-p/504483#M11542</link>
      <description>&lt;P&gt;Is there a workaround for this?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2020 19:08:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Possible-bug-with-changing-permission-on-source-based-field/m-p/504483#M11542</guid>
      <dc:creator>dbot2001</dc:creator>
      <dc:date>2020-06-15T19:08:06Z</dc:date>
    </item>
  </channel>
</rss>

