- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
So I have an application that runs as a docker container in AWS ECS Fargate, and in log configurations for the container , I have used splunk log driver , here I have used --log-opt env to let say set a variable xyz, this variable appears now in the logs under attrs.xyz but I don't want to search everytime using this , so I used field alias in the settings -> fields -> new filed aliases and created xyz = attrs.xyz, but now I have created this field alias and I can't see it (use it to filter the search) but admin user can see this field although correct app - search was selected , and read permission to everyone was given
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Ask your admin if you have Power User or equivalent permissions to share knowledge objects. Without such permissions, you can only create and manage your own. (Manage knowledge object permissions can give you some ideas.)
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No , just one guy with admin access is able to see it. Everyone is able to see attrs.xyz but not xyz ( which I created as field alias [xyz as attrs.xyz] ) yeah application scope is set to search and also , in permissions , global sharing are set with read access to everyone
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Ask your admin if you have Power User or equivalent permissions to share knowledge objects. Without such permissions, you can only create and manage your own. (Manage knowledge object permissions can give you some ideas.)
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

A shot in the dark about "read permission to everyone was given."
- Does everyone see attrs.xyz? If not, that's the first place to troubleshoot.
- If every one sees attrs.xyz but not xyz, can you elaborate what permissions are shown in Splunk? If I'm not mistaken, field aliases restrict permissions by application scope, not by user group or privilege. Is Sharing set to "Global" or is it in a specific application?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

I'm confused. This means that my answer is incorrect. So the problem isn't solved.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Naah the answer that you posted , i shared that with the admin user and did the trick
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Regarding knowledge objects thanks ✌️
