<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why do two different users using same Sh, same app, same query, and same permissions, getting two different results? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-do-two-different-users-using-same-Sh-same-app-same-query-and/m-p/491061#M137107</link>
    <description>&lt;P&gt;Hi @muizash,&lt;BR /&gt;
try to use a past time frame (e.g. yesterday or last hour), in other words not latest=now and see if you continue to have different results.&lt;BR /&gt;
Probably the difference is in the last ingested logs.&lt;/P&gt;

&lt;P&gt;Ciao.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
    <pubDate>Tue, 19 Nov 2019 07:40:38 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2019-11-19T07:40:38Z</dc:date>
    <item>
      <title>Why do two different users using same Sh, same app, same query, and same permissions, getting two different results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-do-two-different-users-using-same-Sh-same-app-same-query-and/m-p/491058#M137104</link>
      <description>&lt;P&gt;Why 2 different users using same Searchhead, same app and same query and same permissions get 2 different results?&lt;BR /&gt;
Could you please write in points the things I should troubleshoot.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2019 05:45:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-do-two-different-users-using-same-Sh-same-app-same-query-and/m-p/491058#M137104</guid>
      <dc:creator>muizash</dc:creator>
      <dc:date>2019-11-19T05:45:13Z</dc:date>
    </item>
    <item>
      <title>Re: Why do two different users using same Sh, same app, same query, and same permissions, getting two different results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-do-two-different-users-using-same-Sh-same-app-same-query-and/m-p/491059#M137105</link>
      <description>&lt;P&gt;Can search statements be published?&lt;BR /&gt;
Also check if there is an error in "Search Job Inspector".&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2019 06:10:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-do-two-different-users-using-same-Sh-same-app-same-query-and/m-p/491059#M137105</guid>
      <dc:creator>HiroshiSatoh</dc:creator>
      <dc:date>2019-11-19T06:10:29Z</dc:date>
    </item>
    <item>
      <title>Re: Why do two different users using same Sh, same app, same query, and same permissions, getting two different results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-do-two-different-users-using-same-Sh-same-app-same-query-and/m-p/491060#M137106</link>
      <description>&lt;P&gt;I checked and found out that the user with less event count, the query is not able to fetch one particular sourcetype. How to edit permissions? @HiroshiSatoh &lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2019 07:05:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-do-two-different-users-using-same-Sh-same-app-same-query-and/m-p/491060#M137106</guid>
      <dc:creator>muizash</dc:creator>
      <dc:date>2019-11-19T07:05:01Z</dc:date>
    </item>
    <item>
      <title>Re: Why do two different users using same Sh, same app, same query, and same permissions, getting two different results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-do-two-different-users-using-same-Sh-same-app-same-query-and/m-p/491061#M137107</link>
      <description>&lt;P&gt;Hi @muizash,&lt;BR /&gt;
try to use a past time frame (e.g. yesterday or last hour), in other words not latest=now and see if you continue to have different results.&lt;BR /&gt;
Probably the difference is in the last ingested logs.&lt;/P&gt;

&lt;P&gt;Ciao.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2019 07:40:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-do-two-different-users-using-same-Sh-same-app-same-query-and/m-p/491061#M137107</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2019-11-19T07:40:38Z</dc:date>
    </item>
    <item>
      <title>Re: Why do two different users using same Sh, same app, same query, and same permissions, getting two different results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-do-two-different-users-using-same-Sh-same-app-same-query-and/m-p/491062#M137108</link>
      <description>&lt;P&gt;I checked and found out that the user with less event count, the query is not able to fetch one particular sourcetype. How to edit permissions? @gcusello &lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2019 03:40:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-do-two-different-users-using-same-Sh-same-app-same-query-and/m-p/491062#M137108</guid>
      <dc:creator>muizash</dc:creator>
      <dc:date>2019-11-20T03:40:01Z</dc:date>
    </item>
    <item>
      <title>Re: Why do two different users using same Sh, same app, same query, and same permissions, getting two different results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-do-two-different-users-using-same-Sh-same-app-same-query-and/m-p/491063#M137109</link>
      <description>&lt;P&gt;Hi @muizash,&lt;BR /&gt;
sourcetypes haven't an owner or grants.&lt;BR /&gt;
But they are in an App, so go in [Settings -- Sourcetypes] and see in what App is your sourcetype.&lt;BR /&gt;
Then go in [Apps -- Manage Apps -- Permissions] and enable that App for the roles you need.&lt;/P&gt;

&lt;P&gt;Ciao.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2019 08:12:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-do-two-different-users-using-same-Sh-same-app-same-query-and/m-p/491063#M137109</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2019-11-20T08:12:19Z</dc:date>
    </item>
    <item>
      <title>Re: Why do two different users using same Sh, same app, same query, and same permissions, getting two different results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-do-two-different-users-using-same-Sh-same-app-same-query-and/m-p/491064#M137110</link>
      <description>&lt;P&gt;Hi @gcusello &lt;BR /&gt;
I found that app is "learned" for that particular sourcetype.&lt;/P&gt;

&lt;P&gt;As i mentioned both users have same set of permission, if permission was the issue, why would other person be able to see the sourcetype results?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2019 08:41:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-do-two-different-users-using-same-Sh-same-app-same-query-and/m-p/491064#M137110</guid>
      <dc:creator>muizash</dc:creator>
      <dc:date>2019-11-21T08:41:14Z</dc:date>
    </item>
    <item>
      <title>Re: Why do two different users using same Sh, same app, same query, and same permissions, getting two different results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-do-two-different-users-using-same-Sh-same-app-same-query-and/m-p/491065#M137111</link>
      <description>&lt;P&gt;Hi @muizash,&lt;BR /&gt;
did you checked if the people that see the sourcetype has the same grants ot the ones with problems?&lt;BR /&gt;
In addition, please check if in the search you're analyzing there are knowledge objects (fields, tags, eventtypes, etc...) with different grants for the two kind of users, maybe the problem is in one of these objects.&lt;BR /&gt;
In particular see if there's one or more knowledge object used in searches or in dedup or in stats.&lt;/P&gt;

&lt;P&gt;Ciao.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2019 09:03:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-do-two-different-users-using-same-Sh-same-app-same-query-and/m-p/491065#M137111</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2019-11-21T09:03:32Z</dc:date>
    </item>
    <item>
      <title>Re: Why do two different users using same Sh, same app, same query, and same permissions, getting two different results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-do-two-different-users-using-same-Sh-same-app-same-query-and/m-p/491066#M137112</link>
      <description>&lt;P&gt;I cloned the user that was not able to search the complete data, gave him different username and name, and now he started fetching all the data. &lt;/P&gt;

&lt;P&gt;THis is quiet strange by Splunk.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2019 02:01:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-do-two-different-users-using-same-Sh-same-app-same-query-and/m-p/491066#M137112</guid>
      <dc:creator>muizash</dc:creator>
      <dc:date>2019-11-26T02:01:08Z</dc:date>
    </item>
  </channel>
</rss>

