Getting Data In

Do you receive results from cisco_wsa_squid and Cisco_firewall when you run search as sourcetype=cisco* user=*?

Gummyworm4
New Member

When you create field aliases cs_username = user in sourcetype cisco_wsa_squid and Username = user in sourcetype cisco_firewall and perform a search like sourcetype=cisco* user=*, do you receive results from both sourcetype?
I see results from one sourcetype cisco_wsa-squid.

0 Karma

woodcock
Esteemed Legend

You must consider the scope of effect of these field alias settings.
If the sharing settings are "private", you must be the user running the search.
If the sharing setting are "app", you must be inside the app context when running the search.
If the sharing settings are "global", then it should work everywhere for everyone.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...