Splunk Enterprise Security

metadata/local.meta question

d_lim
Path Finder

Hello, so I was looking at my metadata/local.meta and it is only the following 4 lines:

[savedsearches/mysavedsearch]
owner = myaccount
version = <something>
modtime = <something>

From the splunk web it shows that the savedsearch is of "App" sharing.

My question is, shouldn't there be a setting there as: export = none

Trying to find out how the savedsearch was created, what causes the creation of savedsearch to not have the export configurations?

Labels (1)
Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

if you have write access to app you can save your saved searches under .../etc/apps/<app name>/local this implicitly means that it’s export=none. If you haven’t that access then those are under .../etc/users/<user>/<app>/local. And if you have access to share KOs to global then those are written to that first directory and to local.meta is added export=system.

r. Ismo

0 Karma

thambisetty
SplunkTrust
SplunkTrust

you are right, as per the docs, it should be there export=none.

I see lookup shared global but there is no export=system in test machine.

I did couple of testings with savedsearch and I can  see export=none when I change sharing from private to App.

 

————————————
If this helps, give a like below.
0 Karma

d_lim
Path Finder

Yep, there should be the "export=none/system"

My issue was that there isn't. On the splunk web it shows as "App" sharing however.

I'm trying to figure out why or what causes it to not have the line "export=none/system"

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...