<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic metadata/local.meta question in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/metadata-local-meta-question/m-p/518635#M9242</link>
    <description>&lt;P&gt;Hello, so I was looking at my metadata/local.meta and it is only the following 4 lines:&lt;/P&gt;&lt;P&gt;[savedsearches/mysavedsearch]&lt;BR /&gt;owner = myaccount&lt;BR /&gt;version = &amp;lt;something&amp;gt;&lt;BR /&gt;modtime = &amp;lt;something&amp;gt;&lt;/P&gt;&lt;P&gt;From the splunk web it shows that the savedsearch is of "App" sharing.&lt;/P&gt;&lt;P&gt;My question is, shouldn't there be a setting there as: export = none&lt;/P&gt;&lt;P&gt;Trying to find out how the savedsearch was created, what causes the creation of savedsearch to not have the export configurations?&lt;/P&gt;</description>
    <pubDate>Wed, 09 Sep 2020 09:32:10 GMT</pubDate>
    <dc:creator>d_lim</dc:creator>
    <dc:date>2020-09-09T09:32:10Z</dc:date>
    <item>
      <title>metadata/local.meta question</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/metadata-local-meta-question/m-p/518635#M9242</link>
      <description>&lt;P&gt;Hello, so I was looking at my metadata/local.meta and it is only the following 4 lines:&lt;/P&gt;&lt;P&gt;[savedsearches/mysavedsearch]&lt;BR /&gt;owner = myaccount&lt;BR /&gt;version = &amp;lt;something&amp;gt;&lt;BR /&gt;modtime = &amp;lt;something&amp;gt;&lt;/P&gt;&lt;P&gt;From the splunk web it shows that the savedsearch is of "App" sharing.&lt;/P&gt;&lt;P&gt;My question is, shouldn't there be a setting there as: export = none&lt;/P&gt;&lt;P&gt;Trying to find out how the savedsearch was created, what causes the creation of savedsearch to not have the export configurations?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2020 09:32:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/metadata-local-meta-question/m-p/518635#M9242</guid>
      <dc:creator>d_lim</dc:creator>
      <dc:date>2020-09-09T09:32:10Z</dc:date>
    </item>
    <item>
      <title>Re: metadata/local.meta question</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/metadata-local-meta-question/m-p/518647#M9243</link>
      <description>&lt;P&gt;you are right, as per the docs, it should be there export=none.&lt;/P&gt;&lt;P&gt;I see lookup shared global but there is no export=system in test machine.&lt;/P&gt;&lt;P&gt;I did couple of testings with savedsearch and I can&amp;nbsp; see export=none when I change sharing from private to App.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2020 10:31:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/metadata-local-meta-question/m-p/518647#M9243</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-09-09T10:31:45Z</dc:date>
    </item>
    <item>
      <title>Re: metadata/local.meta question</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/metadata-local-meta-question/m-p/518731#M9244</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;if you have write access to app you can save your saved searches under .../etc/apps/&amp;lt;app name&amp;gt;/local this implicitly means that it’s export=none. If you haven’t that access then those are under .../etc/users/&amp;lt;user&amp;gt;/&amp;lt;app&amp;gt;/local. And if you have access to share KOs to global then those are written to that first directory and to local.meta is added export=system.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2020 16:29:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/metadata-local-meta-question/m-p/518731#M9244</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-09-09T16:29:56Z</dc:date>
    </item>
    <item>
      <title>Re: metadata/local.meta question</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/metadata-local-meta-question/m-p/518781#M9245</link>
      <description>&lt;P&gt;Yep, there should be the "export=none/system"&lt;/P&gt;&lt;P&gt;My issue was that there isn't. On the splunk web it shows as "App" sharing however.&lt;/P&gt;&lt;P&gt;I'm trying to figure out why or what causes it to not have the line "export=none/system"&lt;/P&gt;</description>
      <pubDate>Thu, 10 Sep 2020 01:21:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/metadata-local-meta-question/m-p/518781#M9245</guid>
      <dc:creator>d_lim</dc:creator>
      <dc:date>2020-09-10T01:21:18Z</dc:date>
    </item>
  </channel>
</rss>

