Where as the first column is username, ipaddress, time and url user visit. I already successfully modified props.conf and transform.conf to map csv fields. In splunk i have user account setup for firstname.lastname@example.org, email@example.com and firstname.lastname@example.org. Is there a way when user a logged in he can only search information which only relevant to him so is with email@example.com and firstname.lastname@example.org. In another word when user email@example.com logged in when he type * or any search term or command so in background it will automatically prepend and run
firstname.lastname@example.org | search *
I think that you'd need to set that up statically as a 'search restriction' property for each role within Splunk. I.e. each user must have its own role. Workable if you 20 users, but not if you have 200.