What does user="-" mean?


Why is user null and what does it mean? Where is this hit coming from?

Tags (2)
0 Karma


ok the solution is simple user is null because it contain splunk action that contain dash
it mean contain user that are not specific in index=_internal
actually you can see this hit on "sourcetype=splunk_web_access" and sourcetype=splunk_access" on index=_internal

0 Karma

Revered Legend

I guess its for Splunk actions which are not user specific. You might be seeing this on "sourcetype=splunk_web_access" and "sourcetype=splunk_access" on index=_internal

0 Karma


What logs did you see this happen in? Does the log contain any other information about the connection? You might be able to use something like a source IP address to assist in attribution.

0 Karma
Get Updates on the Splunk Community!

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...

IM Landing Page Filter - Now Available

We’ve added the capability for you to filter across the summary details on the main Infrastructure Monitoring ...

Dynamic Links from Alerts to IM Navigators - New in Observability Cloud

Splunk continues to improve the troubleshooting experience in Observability Cloud with this latest enhancement ...