I'm on a cluster and I've added a field extraction via the setting ui. The extraction ended up in apps/search/local/props.conf under [splunkd]. The extraction works fine for me but when other users use splunk they don't see the extracted fields.
Turns out I was setting a props.conf in users
View solution in original post