All Apps and Add-ons

SA-nix - Global Searches

BP9906
Builder

Why is the SA-nix app hidden, yet all its saved searches are made global to Splunk? Now all my apps on my search head/indexer show all these searches.

I dont want to break the Splunk App for Unix/Linux but I cant have the searches visible to all users.

0 Karma

araitz
Splunk Employee
Splunk Employee

This is by design. The unix app uses a TA and SA for knowledge objects.

If you don't want users to be able to see the searches in the SA, change the permissions on the SA, but of course the users won't be able to access the unix app either, so you should make sure they don't have permission to that app either.

0 Karma

araitz
Splunk Employee
Splunk Employee

The app depends on the presence of the SA and TA because those add-ons contain important search-time knowledge such as event types, macros, field extractions, and saved searches.

0 Karma

BP9906
Builder

Is that because these searches are used in the TA and App too?

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...