Splunk Enterprise Security

Help with with saving selected fields per user.

dood9999
Explorer

I am looking for help with Splunk configurations that the documentation does not seem to provide and can not be found on Splunk Answers.

The problem is selected fields are not persisting between sessions/alerts.

I know this is possible since my old version of Splunk has this ability.

Ex.

1. User clicks on drilldown search for Notable Event. User marks Selected Fields to use.

2. User closes tab and reopens the same drilldown search for that Notable Event.

3. Selected Fields are gone and it is back to its default state.

How do I get selected fields to save per user?

Labels (2)
0 Karma

meetmshah
SplunkTrust
SplunkTrust

Hello @dood9999, Would you be able to elaborate the question in detail along with few screenshots?

0 Karma

dood9999
Explorer

I will not be able to give screenshots but the issue was larger than just selected fields. It was no data was saving on a per user basis. This includes selected fields, search mode, and many other things.

I found in another thread that the newer versions of Splunk come with an "Optimizations" script that disables these by default and in the documentation it states to not disable this. However in the thread the Splunk guy said this optimization was meant for environments with over 1000 users. My environment has a handful of users so disabling has not caused any issues so far.

This has fixed my issues of saved data not persisting for each user. However, If it is possible I would like to keep the optimizations but then disable certain features that it is optimizing.

is that possible?

Example: Only optimizing search mode since verbose could theoretically take the most processing power.

I hope I have explained this enough.


Edit: Here is the thread I spoke about - https://community.splunk.com/t5/Dashboards-Visualizations/9-0-5-ui-prefs-conf-Why-my-default-search-...

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...