I am using Splunk to document itself within app dashboards and one of the searches I am using is | rest /services/configs/conf-transforms. Users have no trouble accessing other rest resources but when this is added, users don't have access (only admin appears to have access). The current import capabilities I have set for users are listed below, what am I missing????
Also tried | rest /servicesNS/nobody/search/configs/conf-transforms which admin was able to access but users with settings above couldn't.
You could use the
btool search command supplied in the SoS app: http://apps.splunk.com/app/748/
Using that, even regular users can load a list of transforms.conf settings, you can filter by app and stanza name.
btool from the SOS app does not appear to see my app. I changed permissions on the command and can run it but it seems limited to what it can see. The transforms I am trying to see is in a custom app.
Can the user access the app and the transforms configuration in it, e.g. field transforms, through the UI?
Odd. Over here the
btool command can see custom apps, such as dbx or sideview_utils - both as admin and as a regular user.
I take that back. I can not see my transforms in the UI, even as admin. They are working.... I would guess permission issue but don't know where to look.
this is in etc/apps/search/local/transforms.conf
it appears to only see the transforms in /etc/system/local/transforms.conf??
sample from transforms.conf
DELIMS = "\t"
FIELDS = ts, uid, id.origh, id.origp, id.resph, id.respp, proto, service, duration, origbytes, respbytes, connstate, localorig, missedbytes, history, origpkts, origipbytes, resppkts, respipbytes, tunnelparents
I don't think
FIELDS are meant to be visible through the regular Splunk UI.
I've added your stanza to my etc/apps/search/local/transforms.conf and these two searches can both see it:
| rest /services/configs/conf-transforms | search title=bro-conn-2014 | btool transforms | search stanza=bro-conn-2014
That's from an admin, a regular user can not see results from
rest but he can see results from