Security

What does user="-" mean?

rana_nour
Explorer

Why is user null and what does it mean? Where is this hit coming from?

Tags (2)
0 Karma

juvetm
Communicator

ok the solution is simple user is null because it contain splunk action that contain dash
it mean contain user that are not specific in index=_internal
actually you can see this hit on "sourcetype=splunk_web_access" and sourcetype=splunk_access" on index=_internal

0 Karma

somesoni2
Revered Legend

I guess its for Splunk actions which are not user specific. You might be seeing this on "sourcetype=splunk_web_access" and "sourcetype=splunk_access" on index=_internal

0 Karma

Fallingacorn
Engager

What logs did you see this happen in? Does the log contain any other information about the connection? You might be able to use something like a source IP address to assist in attribution.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...