Hi,
I'm trying to get the Splunk user that making changes in kv store. I tried to use the rest call but the User_Name fields return "undefined". I launch this search from javascript.
| inputlookup open_cases
| eval Notes=if(_key=\"" + key + "\",\"" + mod_notes + "\",Notes), Status=\"Work-in-progress\"
| appendcols [ | rest /services/authentication/current-context | rename username AS User_Name | fields User_Name]
| search _key=\"" + key + "\"
| outputlookup open_cases append=true | eval key=_key
Can you help me to get the right username value?
Thanks,
Mauro