Splunk Enterprise Security

Why does Enterprise Security 3.0 not see the tags or field aliases properly in Splunk 6.0 or 6.1?

chrishatfield21
Path Finder

I have Splunk Enterprise 6.1, I've had the same issue on 6.0, and Enterprise Security 3.0 running. I pull in a datasource like normal and everything is looking good until I create tags and field aliases. If I create them in the Search and Reporting app, or any other as long as it is not ES, and I share them globally with everyone having read permissions ES does not see the tags. I can search in any app other then ES and the tags work. If I search inside the ES app context with the same search as before it does not produce any results. The field aliases have the same behavior as the tags when searching.

0 Karma

derekarnold
Communicator

Make sure ES is importing the app properly, see this thread for more info

http://docs.splunk.com/Documentation/ES/3.3.0/Install/InstallTechnologyAdd-ons#Add_a_custom_add-on_t...

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...