Splunk Enterprise Security

Why does Enterprise Security 3.0 not see the tags or field aliases properly in Splunk 6.0 or 6.1?

chrishatfield21
Path Finder

I have Splunk Enterprise 6.1, I've had the same issue on 6.0, and Enterprise Security 3.0 running. I pull in a datasource like normal and everything is looking good until I create tags and field aliases. If I create them in the Search and Reporting app, or any other as long as it is not ES, and I share them globally with everyone having read permissions ES does not see the tags. I can search in any app other then ES and the tags work. If I search inside the ES app context with the same search as before it does not produce any results. The field aliases have the same behavior as the tags when searching.

0 Karma

derekarnold
Communicator

Make sure ES is importing the app properly, see this thread for more info

http://docs.splunk.com/Documentation/ES/3.3.0/Install/InstallTechnologyAdd-ons#Add_a_custom_add-on_t...

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Building Momentum: Splunk Developer Program at .conf25

At Splunk, developers are at the heart of innovation. That’s why this year at .conf25, we officially launched ...