Splunk Enterprise Security

metadata/local.meta question

d_lim
Path Finder

Hello, so I was looking at my metadata/local.meta and it is only the following 4 lines:

[savedsearches/mysavedsearch]
owner = myaccount
version = <something>
modtime = <something>

From the splunk web it shows that the savedsearch is of "App" sharing.

My question is, shouldn't there be a setting there as: export = none

Trying to find out how the savedsearch was created, what causes the creation of savedsearch to not have the export configurations?

Labels (1)
Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

if you have write access to app you can save your saved searches under .../etc/apps/<app name>/local this implicitly means that it’s export=none. If you haven’t that access then those are under .../etc/users/<user>/<app>/local. And if you have access to share KOs to global then those are written to that first directory and to local.meta is added export=system.

r. Ismo

0 Karma

thambisetty
SplunkTrust
SplunkTrust

you are right, as per the docs, it should be there export=none.

I see lookup shared global but there is no export=system in test machine.

I did couple of testings with savedsearch and I can  see export=none when I change sharing from private to App.

 

————————————
If this helps, give a like below.
0 Karma

d_lim
Path Finder

Yep, there should be the "export=none/system"

My issue was that there isn't. On the splunk web it shows as "App" sharing however.

I'm trying to figure out why or what causes it to not have the line "export=none/system"

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...