Splunk Search

search result issue by users

moonyoungjung
New Member

Same SPL result is different by user A and admin

SPL-> index=xxx

when I do search with userA's userid

"interesting fields" when searching with userA's ID and the results when searching with admin are different

so I was create new userID -> userB and assigned same role as userA
userB's search result is exactly the same result as admin

how to fix userA's search result problem?

alt text
admin result

alt text
UserA result

I was look up field1 value.
field1 is dst_ip

Tags (1)
0 Karma
1 Solution

solarboyz1
Builder

Users can create private knowledge objects for parsing events. If so, it would only impact that user.

Via the UI, you can look for private objects (field extrations, sourcetype renames, etc..) owned by userA:
Settings -> All Configuraitons

Or check the config files in their user directory $SPLUNK_HOME/etc/users/userA

View solution in original post

0 Karma

solarboyz1
Builder

Users can create private knowledge objects for parsing events. If so, it would only impact that user.

Via the UI, you can look for private objects (field extrations, sourcetype renames, etc..) owned by userA:
Settings -> All Configuraitons

Or check the config files in their user directory $SPLUNK_HOME/etc/users/userA

0 Karma

moonyoungjung
New Member

I appreciate your help.

0 Karma

moonyoungjung
New Member

I appreciate your help !!

0 Karma

solarboyz1
Builder

Glad it it worked for you!

0 Karma

solarboyz1
Builder

Did it work?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...