<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Enterprise Security: Lookups and other props/transforms in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Lookups-and-other-props-transforms/m-p/388109#M4120</link>
    <description>&lt;P&gt;Also remember... &lt;BR /&gt;
   The behavior has changed with ES 6.0. ES no longer explicitly imports apps using the naming convention. It has reverted to requiring configuration to be exported to system in order to see the configuration.. So which answer is correct depends on which version of ES you are working with.&lt;/P&gt;</description>
    <pubDate>Tue, 21 Jan 2020 21:14:49 GMT</pubDate>
    <dc:creator>cgardiner</dc:creator>
    <dc:date>2020-01-21T21:14:49Z</dc:date>
    <item>
      <title>Splunk Enterprise Security: Lookups and other props/transforms</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Lookups-and-other-props-transforms/m-p/388106#M4117</link>
      <description>&lt;P&gt;Hello, &lt;/P&gt;

&lt;P&gt;I've run into an issue lately where I want both my search heads and Enterprise Security to show the same field extractions and use the same lookups to sync the data across the components/data sources.&lt;/P&gt;

&lt;P&gt;However, I'm finding that unless I add a lookup/props.conf/transforms.conf to one of Enterprise Security's stock apps (ex. SplunkEnterpriseSecuritySuite or any of the ES SA's), my extracted fields and lookups will only show in an Enterprise Security search and not on any other app searches.&lt;/P&gt;

&lt;P&gt;For administrative purposes, I'd like to keep these files specific to the app, and then just control the permissions to either Global or App based. In this case, I want them to be global. Has anyone else run into this issue or am I doing something wrong here? If I add a props/transform/lookup field outside the base ES apps, my ES searches are missing these fields/enrichment. This is not the same behavior as any other app I've worked with or any of the base Splunk apps.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2019 14:38:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Lookups-and-other-props-transforms/m-p/388106#M4117</guid>
      <dc:creator>arlombar</dc:creator>
      <dc:date>2019-04-02T14:38:38Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Lookups and other props/transforms</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Lookups-and-other-props-transforms/m-p/388107#M4118</link>
      <description>&lt;P&gt;Knowledge objects have permissions. Set the permissions on your extractions and lookups by by packaging them inside an app of your own (useful if you plan to rev these often/distribute them), then adding the following to a metadata/default.meta file inside the app.&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;&lt;BR /&gt;
[]&lt;BR /&gt;
export=system&lt;BR /&gt;
&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.5/Admin/Defaultmetaconf"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.5/Admin/Defaultmetaconf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2019 16:20:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Lookups-and-other-props-transforms/m-p/388107#M4118</guid>
      <dc:creator>vnakra_splunk</dc:creator>
      <dc:date>2019-04-02T16:20:14Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Lookups and other props/transforms</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Lookups-and-other-props-transforms/m-p/388108#M4119</link>
      <description>&lt;P&gt;Also, by default, ES imports apps that start with TA-&lt;EM&gt;, SA-&lt;/EM&gt;, Splunk_*   . So, if your app is following a diff name, you would need to add your app/add-on to the import, as per  &lt;A href="https://docs.splunk.com/Documentation/ES/5.2.2/Install/ImportCustomApps"&gt;https://docs.splunk.com/Documentation/ES/5.2.2/Install/ImportCustomApps&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;This will ensure your app is visible within the context of ES. You can then update local.meta with required permissions for any knowledge objects to control the visibility.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2019 22:05:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Lookups-and-other-props-transforms/m-p/388108#M4119</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2019-04-02T22:05:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Lookups and other props/transforms</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Lookups-and-other-props-transforms/m-p/388109#M4120</link>
      <description>&lt;P&gt;Also remember... &lt;BR /&gt;
   The behavior has changed with ES 6.0. ES no longer explicitly imports apps using the naming convention. It has reverted to requiring configuration to be exported to system in order to see the configuration.. So which answer is correct depends on which version of ES you are working with.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2020 21:14:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Lookups-and-other-props-transforms/m-p/388109#M4120</guid>
      <dc:creator>cgardiner</dc:creator>
      <dc:date>2020-01-21T21:14:49Z</dc:date>
    </item>
  </channel>
</rss>

