Splunk Enterprise Security

metadata/local.meta question

d_lim
Path Finder

Hello, so I was looking at my metadata/local.meta and it is only the following 4 lines:

[savedsearches/mysavedsearch]
owner = myaccount
version = <something>
modtime = <something>

From the splunk web it shows that the savedsearch is of "App" sharing.

My question is, shouldn't there be a setting there as: export = none

Trying to find out how the savedsearch was created, what causes the creation of savedsearch to not have the export configurations?

Labels (1)
Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

if you have write access to app you can save your saved searches under .../etc/apps/<app name>/local this implicitly means that it’s export=none. If you haven’t that access then those are under .../etc/users/<user>/<app>/local. And if you have access to share KOs to global then those are written to that first directory and to local.meta is added export=system.

r. Ismo

0 Karma

thambisetty
Super Champion

you are right, as per the docs, it should be there export=none.

I see lookup shared global but there is no export=system in test machine.

I did couple of testings with savedsearch and I can  see export=none when I change sharing from private to App.

 

————————————
If this helps, give a like below.
0 Karma

d_lim
Path Finder

Yep, there should be the "export=none/system"

My issue was that there isn't. On the splunk web it shows as "App" sharing however.

I'm trying to figure out why or what causes it to not have the line "export=none/system"

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!