Getting Data In

Do you receive results from cisco_wsa_squid and Cisco_firewall when you run search as sourcetype=cisco* user=*?

Gummyworm4
New Member

When you create field aliases cs_username = user in sourcetype cisco_wsa_squid and Username = user in sourcetype cisco_firewall and perform a search like sourcetype=cisco* user=*, do you receive results from both sourcetype?
I see results from one sourcetype cisco_wsa-squid.

0 Karma

woodcock
Esteemed Legend

You must consider the scope of effect of these field alias settings.
If the sharing settings are "private", you must be the user running the search.
If the sharing setting are "app", you must be inside the app context when running the search.
If the sharing settings are "global", then it should work everywhere for everyone.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...