Getting Data In

default.meta [views\setup]

splunkreal
Motivator

Hello guys,
Does anyone know what views\setup found in default.meta means?

Also if Search & Reporting app default.meta differs by Splunk versions? Is it OK to provide our own logic?

In our configuration, users were not able to share their report (savedsearches)

Thanks.

* If this helps, please upvote or accept solution if it solved *
0 Karma
1 Solution

nickhills
Ultra Champion

The setup dashboard [views\setup] is a special kind of dashboard used when an app is first installed.
You would be well advised to not change its settings as you could expose admin functions to non-admin users.

As a general rule. Do Not modify default.meta.
If you need to make advanced changes to permissions make the changes in local.meta

If my comment helps, please give it a thumbs up!

View solution in original post

nickhills
Ultra Champion

The setup dashboard [views\setup] is a special kind of dashboard used when an app is first installed.
You would be well advised to not change its settings as you could expose admin functions to non-admin users.

As a general rule. Do Not modify default.meta.
If you need to make advanced changes to permissions make the changes in local.meta

If my comment helps, please give it a thumbs up!

13tsavage
Communicator

Consult the Splunk Docs on default.meta.conf.spec and read up on what your own configurations would do to app ownership information, access controls, and export settings for Splunk objects like saved searches, event types, and views.

See the link here:
default.meta.conf.spec

0 Karma

splunkreal
Motivator

Hello, nothing about \setup in the doc?

* If this helps, please upvote or accept solution if it solved *
0 Karma

13tsavage
Communicator

there is a default.meta shipped with each unique app. In which app do you see a default.meta with a [views/setup]?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...