Getting Data In

Do you receive results from cisco_wsa_squid and Cisco_firewall when you run search as sourcetype=cisco* user=*?

Gummyworm4
New Member

When you create field aliases cs_username = user in sourcetype cisco_wsa_squid and Username = user in sourcetype cisco_firewall and perform a search like sourcetype=cisco* user=*, do you receive results from both sourcetype?
I see results from one sourcetype cisco_wsa-squid.

0 Karma

woodcock
Esteemed Legend

You must consider the scope of effect of these field alias settings.
If the sharing settings are "private", you must be the user running the search.
If the sharing setting are "app", you must be inside the app context when running the search.
If the sharing settings are "global", then it should work everywhere for everyone.

0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...