Splunk Enterprise Security

Why do I receive different results between two different applications?

jwhughes58
Contributor

I have a simple search

index=myIndex sourcetype=mySourcetype

If I run the search in the Splunk Enterprise Security app I get src_ip. If I run the search in a different app, I don't get src_ip. I need leads on how to figure out why this is happening. Any leads?

TIA,
Joe

0 Karma
1 Solution

dineshraj9
Builder

Check Fields -> Extractions in the Splunk Enterprise Security App. There would be an EXTRACT written to extract such fields. You can add the same in your app or set the permissions of the existing EXTRACT to global to leverage the same behaviour across all apps.

View solution in original post

dineshraj9
Builder

Check Fields -> Extractions in the Splunk Enterprise Security App. There would be an EXTRACT written to extract such fields. You can add the same in your app or set the permissions of the existing EXTRACT to global to leverage the same behaviour across all apps.

jwhughes58
Contributor

It was a permissions issue on the extracts. They were set to app only. When I changed them to global the search in the other app started working.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...