I am stuck at a scenario where if user using search in a specific app, then that app folders name should be shown as a filed.
Is there any way to get current app name using REST or METADATA or any other command ?
| stats count
[| rest /services/search/jobs splunk_server=local
| where sid = info_sid
| rename eai:acl.app as app_name
| fields + app_name]
upvote if this resolves your issue.
View solution in original post