Getting Data In

Do you receive results from cisco_wsa_squid and Cisco_firewall when you run search as sourcetype=cisco* user=*?

Gummyworm4
New Member

When you create field aliases cs_username = user in sourcetype cisco_wsa_squid and Username = user in sourcetype cisco_firewall and perform a search like sourcetype=cisco* user=*, do you receive results from both sourcetype?
I see results from one sourcetype cisco_wsa-squid.

0 Karma

woodcock
Esteemed Legend

You must consider the scope of effect of these field alias settings.
If the sharing settings are "private", you must be the user running the search.
If the sharing setting are "app", you must be inside the app context when running the search.
If the sharing settings are "global", then it should work everywhere for everyone.

0 Karma
Get Updates on the Splunk Community!

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...