<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Acess issue with different users in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Acess-issue-with-different-users/m-p/756974#M23642</link>
    <description>This sounds like your Customer role hasn't defined all access which are needed to get data.&lt;BR /&gt;Can you check what are roles which are needed for display that dashboard including all KOs like macros, eventtypes, reports etc.&lt;BR /&gt;Usually that Oops screen means that this user/role hasn't access to this dashboard/report etc.</description>
    <pubDate>Mon, 05 Jan 2026 12:19:15 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2026-01-05T12:19:15Z</dc:date>
    <item>
      <title>Acess issue with different users</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Acess-issue-with-different-users/m-p/756959#M23636</link>
      <description>&lt;P&gt;Hello Splunkers !!&lt;BR /&gt;&lt;BR /&gt;I'm noticing an issue in Splunk. When I log in with the production manager&lt;STRONG&gt;&amp;nbsp;role&lt;/STRONG&gt;, the report figures are perfectly accurate. But when I access Splunk using a &lt;STRONG&gt;customer role&lt;/STRONG&gt;, the values in the reports differ from what I see as a production manager. Any suggestions on how to troubleshoot or resolve this difference would be appreciated!&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1767605337892.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/41097i8E93B633C2A89FA8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1767605337892.png" alt="uagraw01_0-1767605337892.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_1-1767605359201.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/41098i051E65102BCE8EDB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_1-1767605359201.png" alt="uagraw01_1-1767605359201.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;Correct values with the production manager role&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_4-1767605521217.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/41101i65277BD7022C4185/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_4-1767605521217.png" alt="uagraw01_4-1767605521217.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;wrong values with customer role&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_3-1767605494874.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/41100iEE4890CD725A42EC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_3-1767605494874.png" alt="uagraw01_3-1767605494874.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jan 2026 09:32:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Acess-issue-with-different-users/m-p/756959#M23636</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2026-01-05T09:32:31Z</dc:date>
    </item>
    <item>
      <title>Re: Acess issue with different users</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Acess-issue-with-different-users/m-p/756960#M23637</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/70277"&gt;@uagraw01&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Its suspicious that the results are 4x different between them - I wouldnt expect this to be a capabilities issue but perhaps something else such as one user being able to search multiple indexes, or even a field extraction that one role has access to which another doesnt.&lt;/P&gt;&lt;P&gt;Are you able to confirm which numbers are correct?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you also able to share the search so we can see what might be the issue there? Please redact anything sensitive in the search if you're going to share it.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jan 2026 09:46:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Acess-issue-with-different-users/m-p/756960#M23637</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2026-01-05T09:46:24Z</dc:date>
    </item>
    <item>
      <title>Re: Acess issue with different users</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Acess-issue-with-different-users/m-p/756971#M23641</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;The numbers below are&amp;nbsp;correct, which is Production_manager role.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1767607497699.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/41104i7DE8CA15565657B8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1767607497699.png" alt="uagraw01_0-1767607497699.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;One more thing to add ; while open the panel search in custome role I am getting oops message but in Production manger role panel is working fine and opens in anaother windows.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_1-1767607596951.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/41105iDB4F43860B1C5150/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_1-1767607596951.png" alt="uagraw01_1-1767607596951.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jan 2026 10:07:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Acess-issue-with-different-users/m-p/756971#M23641</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2026-01-05T10:07:38Z</dc:date>
    </item>
    <item>
      <title>Re: Acess issue with different users</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Acess-issue-with-different-users/m-p/756974#M23642</link>
      <description>This sounds like your Customer role hasn't defined all access which are needed to get data.&lt;BR /&gt;Can you check what are roles which are needed for display that dashboard including all KOs like macros, eventtypes, reports etc.&lt;BR /&gt;Usually that Oops screen means that this user/role hasn't access to this dashboard/report etc.</description>
      <pubDate>Mon, 05 Jan 2026 12:19:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Acess-issue-with-different-users/m-p/756974#M23642</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2026-01-05T12:19:15Z</dc:date>
    </item>
    <item>
      <title>Re: Acess issue with different users</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Acess-issue-with-different-users/m-p/756976#M23644</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;I have now given read access to search and reporting app to customer role and now figures are coming similar like production manager role.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jan 2026 12:22:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Acess-issue-with-different-users/m-p/756976#M23644</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2026-01-05T12:22:29Z</dc:date>
    </item>
    <item>
      <title>Re: Acess issue with different users</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Acess-issue-with-different-users/m-p/756978#M23645</link>
      <description>Nice to hear that this solve the issue.&lt;BR /&gt;BTW here is excellent presentation how everyone should manage Splunk access &lt;A href="https://conf.splunk.com/files/2023/slides/PLA1169B.pdf" target="_blank"&gt;https://conf.splunk.com/files/2023/slides/PLA1169B.pdf&lt;/A&gt;&lt;BR /&gt;If you haven't full CI/CD pipeline with needed parts then you could/should somehow simplify this, but in generally speaking this is excellent way to manage RBAC access in Splunk.</description>
      <pubDate>Mon, 05 Jan 2026 12:28:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Acess-issue-with-different-users/m-p/756978#M23645</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2026-01-05T12:28:28Z</dc:date>
    </item>
    <item>
      <title>Re: Acess issue with different users</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Acess-issue-with-different-users/m-p/756989#M23651</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;Thanks for sharing this with me. I will try to accomodate in my environment.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jan 2026 16:07:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Acess-issue-with-different-users/m-p/756989#M23651</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2026-01-05T16:07:51Z</dc:date>
    </item>
    <item>
      <title>Re: Acess issue with different users</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Acess-issue-with-different-users/m-p/756995#M23653</link>
      <description>&lt;P&gt;We don't know what powers those charts but the differences in results when a search is run as users with different roles usually boils down to:&lt;/P&gt;&lt;P&gt;1) Difference in index access permissions (remember that roles can also have search filters)&lt;/P&gt;&lt;P&gt;2) Difference in access to apps in which KOs are defined or even specific KOs.&lt;/P&gt;&lt;P&gt;Also some users have private KOs which can affect what is being extracted/calculated and so on. And sometimes the search behaves differently (has access to different KOs) depending on which app it's being run in.&lt;/P&gt;&lt;P&gt;So there are several possible points where the behaviour could differ.&lt;/P&gt;&lt;P&gt;I'd start with cutting the search to the very initial part (before first pipe) and comparing:&lt;/P&gt;&lt;P&gt;1) Number of results&lt;/P&gt;&lt;P&gt;2) Extracted fields.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jan 2026 19:36:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Acess-issue-with-different-users/m-p/756995#M23653</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2026-01-05T19:36:58Z</dc:date>
    </item>
    <item>
      <title>Re: Acess issue with different users</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Acess-issue-with-different-users/m-p/757002#M23655</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;I’m not using any knowledge objects in the panel search&amp;nbsp; it’s a direct index search. After granting read access to the &lt;STRONG&gt;Search &amp;amp; Reporting&lt;/STRONG&gt; app, the numbers started appearing correctly, consistent with other user roles.&lt;BR /&gt;&lt;BR /&gt;index=json a type=Put data.workstationId=*&lt;BR /&gt;| spath source | search source=decan&lt;BR /&gt;| rename data.putCarrierPhysicalId as BinId, data.orderId as OrderId, data.putCarrierQuantity as qty, data.workstationId as workstation&lt;BR /&gt;| timechart span=1d@d1 sum(qty) as value by workstation&lt;BR /&gt;| addtotals&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jan 2026 03:59:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Acess-issue-with-different-users/m-p/757002#M23655</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2026-01-06T03:59:23Z</dc:date>
    </item>
    <item>
      <title>Re: Acess issue with different users</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Acess-issue-with-different-users/m-p/757003#M23656</link>
      <description>&lt;P&gt;Well, a sourcetype can also be defined within an app to which access might differ between roles.&lt;/P&gt;&lt;P&gt;As a side remark - "data.workstationId=*" is a releatively performance-hungry condition. If you can narrow down your events by specifying the field name (simply adding "workstationId" on its own) as search term - do it. (of course if 95% of your events contain this field it won't help much but if it's just 10%, it will give you a significant savings on search time).&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jan 2026 09:36:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Acess-issue-with-different-users/m-p/757003#M23656</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2026-01-06T09:36:02Z</dc:date>
    </item>
    <item>
      <title>Re: Acess issue with different users</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Acess-issue-with-different-users/m-p/757017#M23660</link>
      <description>IMHO: in any reasonable sized environment you should have separate apps for different business units / systems. Don't use Search And Reporting for anything especially if you have or plan to have SHC environment.</description>
      <pubDate>Wed, 07 Jan 2026 07:34:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Acess-issue-with-different-users/m-p/757017#M23660</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2026-01-07T07:34:06Z</dc:date>
    </item>
  </channel>
</rss>

