Splunk Search

search result issue by users

moonyoungjung
New Member

Same SPL result is different by user A and admin

SPL-> index=xxx

when I do search with userA's userid

"interesting fields" when searching with userA's ID and the results when searching with admin are different

so I was create new userID -> userB and assigned same role as userA
userB's search result is exactly the same result as admin

how to fix userA's search result problem?

alt text
admin result

alt text
UserA result

I was look up field1 value.
field1 is dst_ip

Tags (1)
0 Karma
1 Solution

solarboyz1
Builder

Users can create private knowledge objects for parsing events. If so, it would only impact that user.

Via the UI, you can look for private objects (field extrations, sourcetype renames, etc..) owned by userA:
Settings -> All Configuraitons

Or check the config files in their user directory $SPLUNK_HOME/etc/users/userA

View solution in original post

0 Karma

solarboyz1
Builder

Users can create private knowledge objects for parsing events. If so, it would only impact that user.

Via the UI, you can look for private objects (field extrations, sourcetype renames, etc..) owned by userA:
Settings -> All Configuraitons

Or check the config files in their user directory $SPLUNK_HOME/etc/users/userA

0 Karma

moonyoungjung
New Member

I appreciate your help.

0 Karma

moonyoungjung
New Member

I appreciate your help !!

0 Karma

solarboyz1
Builder

Glad it it worked for you!

0 Karma

solarboyz1
Builder

Did it work?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

How Edge Processor's Durable Queue Works

Edge Processor sits in one of the most consequential places in any Splunk pipeline: between your data sources ...