Hi, If you make a curl request to the Splunk, that in the web_access.log the client is a 127.0.0.1 and user is '-', can we somehow correct client field to know who actually made the request?
@user487596- I have same result for client info, it feels like this is how it designs. But I feel having actual IP would help.
For username, in some events I do see actual username in my case. In some events it is "-".