Splunk Dev

How to make an extracted field from a user account as global field?

akashjohn
Explorer

Hi Team,

I have done a field extraction from a query result and plotted as PIE chart(the dashboard was made as global before creating this particular pie chart) .

When one of my colleague tried to view the pie chart after login with his splunk dashboard credentials it is showing is as no data is available. When I have checked the settings > Fields > Field Extraction we cannot find the field extracted from my user is not showing with the other user.

Could you please let us know how can we make the field extracted by a particular user (here in this case my user) to visible to other users (global field)?

Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

the field proprietary must go in [settings - fields - fields extraction] and then give the correct share properties to the field.
Bye.
Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

the field proprietary must go in [settings - fields - fields extraction] and then give the correct share properties to the field.
Bye.
Giuseppe

akashjohn
Explorer

Hi Giuseppe,

The share property is showing as Private and I cannot find any settings button to change the same. Do we need to navigate to some other place to do change the permission?

Thanks,
Akash

0 Karma

gcusello
SplunkTrust
SplunkTrust

Click on Share and then choose App or Global Level granting the Read access to the Role you like or to all roles, but maintaining the write grant to your role.
Bye.
Giuseppe

0 Karma

akashjohn
Explorer

I think I donot have the permission to modify the permission. I will be checking with the Splunk admin team and try.

0 Karma
Get Updates on the Splunk Community!

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...