All Apps and Add-ons

Problem with Global Permissions on Field

brandonf
Path Finder

Hi

Just a note that your field extraction below has global permission and overwrites other "user" field name extraction. You should make it app permission level only.

default : EVAL-user user md5(clientip."_".http_user_agent)

0 Karma

jbjerke_splunk
Splunk Employee
Splunk Employee

Hi Brandonf

Thanks for reporting this in. There were a also few users who noted this.

There is a new version of the app (1.4) which fixes this issue and adds on some new functionality.
https://splunkbase.splunk.com/app/2699/

j

0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...