Reporting

Can't set report transform as global to all apps

christopherutz
Path Finder

I have a set of report transforms in an application that I am trying to make global so that fields are extracted when inside the context of the application which defines them and any other application. Via the GUI selecting the "All apps" radio button appears to save correctly but going back into the permissions page shows the transform is still permissioned for "This app only". Any ideas what is going on here and/or another way I can set up transforms that will work across all apps?

Tags (1)
0 Karma

Zambonilli
Explorer

I'm running into the same thing with "Global" inline fields. Anyone?

0 Karma

Zambonilli
Explorer

I figured out what was causing my issue. While I would create the extraction in an application and set it to all applications & give read only to everyone; the user also needs to have at least read only access to the application that the extraction is in.

So I usually create all global objects in the Search application because Splunk 4.1.6 beta has a lot of references to this application so I've had nothing but issues with disabling this app anyway. Then I give all roles at least read only access to the search application.

Another option is to add these to the system app.

0 Karma

christopherutz
Path Finder

While I am not sure if this is the correct way to accomplish this, or the most efficent, I found adding the following into metatdata/local.meta seems to do what I want.

[lookups]
export = system

[tags]
export = system

[props]
export = system

[transforms]
export = system

0 Karma

BunnyHop
Contributor

You can create the settings on the CLI and it will, by default, make the permission Global for that setting/setup. To change the permission on the GUI, you will either have to login as Admin or as the owner of the transform config.

0 Karma

christopherutz
Path Finder

Even configuring the transform and REPORT entry via the command line the fields are still only available in the app they are defined within. I am not sure what else to try at this point. I am unable make the extraction global for all applications which means users don't have access to the fields from the default search app as well as the app in which the fields are defined. Any other ideas?

0 Karma

BunnyHop
Contributor

To eliminate duplication, make sure you remove your current transform config on the GUI before you proceed with the CLI.

0 Karma

christopherutz
Path Finder

I've tried to change the permissions via the GUI as admin and I observed the same behavior. I will try via the config next.

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...