Splunk Search

search result issue by users

moonyoungjung
New Member

Same SPL result is different by user A and admin

SPL-> index=xxx

when I do search with userA's userid

"interesting fields" when searching with userA's ID and the results when searching with admin are different

so I was create new userID -> userB and assigned same role as userA
userB's search result is exactly the same result as admin

how to fix userA's search result problem?

alt text
admin result

alt text
UserA result

I was look up field1 value.
field1 is dst_ip

Tags (1)
0 Karma
1 Solution

solarboyz1
Builder

Users can create private knowledge objects for parsing events. If so, it would only impact that user.

Via the UI, you can look for private objects (field extrations, sourcetype renames, etc..) owned by userA:
Settings -> All Configuraitons

Or check the config files in their user directory $SPLUNK_HOME/etc/users/userA

View solution in original post

0 Karma

solarboyz1
Builder

Users can create private knowledge objects for parsing events. If so, it would only impact that user.

Via the UI, you can look for private objects (field extrations, sourcetype renames, etc..) owned by userA:
Settings -> All Configuraitons

Or check the config files in their user directory $SPLUNK_HOME/etc/users/userA

0 Karma

moonyoungjung
New Member

I appreciate your help.

0 Karma

moonyoungjung
New Member

I appreciate your help !!

0 Karma

solarboyz1
Builder

Glad it it worked for you!

0 Karma

solarboyz1
Builder

Did it work?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...