<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Different Performance using admin user or a user with only user role in Security</title>
    <link>https://community.splunk.com/t5/Security/Different-Performance-using-admin-user-or-a-user-with-only-user/m-p/223755#M13555</link>
    <description>&lt;P&gt;Hi aniello_cerrato,&lt;BR /&gt;
you should verify if this user has many active searches at the same time: the only thing I can think is that the role of this user has a maximum number of executable searches less than admin role, so when he executes too many searches the last are queued.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
    <pubDate>Mon, 09 Jan 2017 10:20:48 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2017-01-09T10:20:48Z</dc:date>
    <item>
      <title>Different Performance using admin user or a user with only user role</title>
      <link>https://community.splunk.com/t5/Security/Different-Performance-using-admin-user-or-a-user-with-only-user/m-p/223754#M13554</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have different Performance using admin user and a user with only user role.&lt;/P&gt;

&lt;P&gt;The query is very simple, below the xml of panel.&lt;/P&gt;

&lt;P&gt;What could be the root cause of this behaviour?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
A&lt;/P&gt;

&lt;P&gt;row&amp;gt;&lt;BR /&gt;
    &lt;PANEL&gt;&lt;BR /&gt;
      &lt;TITLE&gt;Scarti per Prodotto&lt;/TITLE&gt;&lt;BR /&gt;
      &lt;CHART&gt;&lt;BR /&gt;
        &lt;TITLE&gt;&lt;/TITLE&gt;&lt;BR /&gt;
        &lt;SEARCH&gt;&lt;BR /&gt;
          &lt;QUERY&gt;sourcetype="cx_import_req_prod" REQUEST_TYPE!="Attivazione" STATUS_CD="Errore" | dedup ROW_ID | stats count by segmento&lt;/QUERY&gt;&lt;BR /&gt;
          &lt;EARLIEST&gt;$last_upd.earliest$&lt;/EARLIEST&gt;&lt;BR /&gt;
          &lt;LATEST&gt;$last_upd.latest$&lt;/LATEST&gt;&lt;BR /&gt;
          &lt;SAMPLERATIO&gt;1&lt;/SAMPLERATIO&gt;&lt;BR /&gt;
        &lt;/SEARCH&gt;&lt;/CHART&gt;&lt;/PANEL&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:20:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Different-Performance-using-admin-user-or-a-user-with-only-user/m-p/223754#M13554</guid>
      <dc:creator>aniello_cerrato</dc:creator>
      <dc:date>2020-09-29T12:20:01Z</dc:date>
    </item>
    <item>
      <title>Re: Different Performance using admin user or a user with only user role</title>
      <link>https://community.splunk.com/t5/Security/Different-Performance-using-admin-user-or-a-user-with-only-user/m-p/223755#M13555</link>
      <description>&lt;P&gt;Hi aniello_cerrato,&lt;BR /&gt;
you should verify if this user has many active searches at the same time: the only thing I can think is that the role of this user has a maximum number of executable searches less than admin role, so when he executes too many searches the last are queued.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2017 10:20:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Different-Performance-using-admin-user-or-a-user-with-only-user/m-p/223755#M13555</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-01-09T10:20:48Z</dc:date>
    </item>
    <item>
      <title>Re: Different Performance using admin user or a user with only user role</title>
      <link>https://community.splunk.com/t5/Security/Different-Performance-using-admin-user-or-a-user-with-only-user/m-p/223756#M13556</link>
      <description>&lt;P&gt;Hi Giuseppe,&lt;/P&gt;

&lt;P&gt;how can verify the number executable searches for my user?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Aniello&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2017 10:29:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Different-Performance-using-admin-user-or-a-user-with-only-user/m-p/223756#M13556</guid>
      <dc:creator>aniello_cerrato</dc:creator>
      <dc:date>2017-01-09T10:29:14Z</dc:date>
    </item>
    <item>
      <title>Re: Different Performance using admin user or a user with only user role</title>
      <link>https://community.splunk.com/t5/Security/Different-Performance-using-admin-user-or-a-user-with-only-user/m-p/223757#M13557</link>
      <description>&lt;P&gt;go to Settings -- Access Control -- Roles -- your role&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2017 11:00:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Different-Performance-using-admin-user-or-a-user-with-only-user/m-p/223757#M13557</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-01-09T11:00:43Z</dc:date>
    </item>
  </channel>
</rss>

