Splunk Search

search result issue by users

moonyoungjung
New Member

Same SPL result is different by user A and admin

SPL-> index=xxx

when I do search with userA's userid

"interesting fields" when searching with userA's ID and the results when searching with admin are different

so I was create new userID -> userB and assigned same role as userA
userB's search result is exactly the same result as admin

how to fix userA's search result problem?

alt text
admin result

alt text
UserA result

I was look up field1 value.
field1 is dst_ip

Tags (1)
0 Karma
1 Solution

solarboyz1
Builder

Users can create private knowledge objects for parsing events. If so, it would only impact that user.

Via the UI, you can look for private objects (field extrations, sourcetype renames, etc..) owned by userA:
Settings -> All Configuraitons

Or check the config files in their user directory $SPLUNK_HOME/etc/users/userA

View solution in original post

0 Karma

solarboyz1
Builder

Users can create private knowledge objects for parsing events. If so, it would only impact that user.

Via the UI, you can look for private objects (field extrations, sourcetype renames, etc..) owned by userA:
Settings -> All Configuraitons

Or check the config files in their user directory $SPLUNK_HOME/etc/users/userA

0 Karma

moonyoungjung
New Member

I appreciate your help.

0 Karma

moonyoungjung
New Member

I appreciate your help !!

0 Karma

solarboyz1
Builder

Glad it it worked for you!

0 Karma

solarboyz1
Builder

Did it work?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...