<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Users unable to see the dashboards irrespective of permissions / roles enabled in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/What-is-the-issue-with-users-unable-to-see-the-dashboards/m-p/621168#M50991</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Thanks for the response. there are no event types / tags or other knowledge objects used in search. The search is using summary index &amp;amp; a saved search to populate data. The user role has read access to both.&lt;/P&gt;</description>
    <pubDate>Thu, 17 Nov 2022 04:33:41 GMT</pubDate>
    <dc:creator>DineshRaja</dc:creator>
    <dc:date>2022-11-17T04:33:41Z</dc:date>
    <item>
      <title>What is the issue with users unable to see the dashboards irrespective of permissions / roles enabled?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/What-is-the-issue-with-users-unable-to-see-the-dashboards/m-p/620990#M50971</link>
      <description>&lt;P&gt;Hi All,&amp;nbsp;&lt;BR /&gt;we have few dashboards which are using summary indexes to populate data. Few users reported that they are unable to see any values when they access respective dashboards (Issue is reproducible as well).&amp;nbsp; However, when I logged in admin user the dashboards are just working fine &amp;amp; values are up to date.&lt;BR /&gt;&lt;BR /&gt;I have validated the roles assigned (authorize.conf) and it seems good and have access to summary indexes.&amp;nbsp;&lt;BR /&gt;[role_example_user]&lt;BR /&gt;srchIndexesAllowed = example_index;example_index2;summary_index1;summary_index2&lt;BR /&gt;srchMaxTime = 144000&lt;BR /&gt;importRoles = default_user&lt;/P&gt;
&lt;P&gt;Also, validated default.meta configs and respective role has read access to the saved searches, views etc.&lt;BR /&gt;&lt;BR /&gt;[savedsearches/summary_index1]&lt;BR /&gt;access = read : [ admin, role_example_user ], write : [ ]&lt;BR /&gt;export = none&lt;BR /&gt;owner = test_user&lt;BR /&gt;&lt;BR /&gt;Still users with respective roles can't see anything on dashboards.&amp;nbsp;&lt;BR /&gt;Please let me know how I can fix this issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2022 14:57:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/What-is-the-issue-with-users-unable-to-see-the-dashboards/m-p/620990#M50971</guid>
      <dc:creator>DineshRaja</dc:creator>
      <dc:date>2022-11-17T14:57:21Z</dc:date>
    </item>
    <item>
      <title>Re: Users unable to see the dashboards irrespective of permissions / roles enabled</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/What-is-the-issue-with-users-unable-to-see-the-dashboards/m-p/621008#M50976</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/251317"&gt;@DineshRaja&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;in your dashboard, are you using some knowledhe object as an eventtype or a tag or some field used in the search?&lt;/P&gt;&lt;P&gt;probably yes, so check the permissions of all these objects and enable the roles you're using.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 07:20:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/What-is-the-issue-with-users-unable-to-see-the-dashboards/m-p/621008#M50976</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-11-16T07:20:32Z</dc:date>
    </item>
    <item>
      <title>Re: Users unable to see the dashboards irrespective of permissions / roles enabled</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/What-is-the-issue-with-users-unable-to-see-the-dashboards/m-p/621012#M50979</link>
      <description>&lt;P&gt;What results do the users get when they open the dashboard search separately?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 07:26:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/What-is-the-issue-with-users-unable-to-see-the-dashboards/m-p/621012#M50979</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-11-16T07:26:27Z</dc:date>
    </item>
    <item>
      <title>Re: Users unable to see the dashboards irrespective of permissions / roles enabled</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/What-is-the-issue-with-users-unable-to-see-the-dashboards/m-p/621168#M50991</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Thanks for the response. there are no event types / tags or other knowledge objects used in search. The search is using summary index &amp;amp; a saved search to populate data. The user role has read access to both.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2022 04:33:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/What-is-the-issue-with-users-unable-to-see-the-dashboards/m-p/621168#M50991</guid>
      <dc:creator>DineshRaja</dc:creator>
      <dc:date>2022-11-17T04:33:41Z</dc:date>
    </item>
    <item>
      <title>Re: Users unable to see the dashboards irrespective of permissions / roles enabled</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/What-is-the-issue-with-users-unable-to-see-the-dashboards/m-p/621169#M50992</link>
      <description>&lt;P&gt;It's always returning zero events as results (0/0) when running with user account. But When I execute same search with Admin account results are having numbers which is expected result ( e.g: 1234/10000).&lt;/P&gt;</description>
      <pubDate>Fri, 18 Nov 2022 06:07:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/What-is-the-issue-with-users-unable-to-see-the-dashboards/m-p/621169#M50992</guid>
      <dc:creator>DineshRaja</dc:creator>
      <dc:date>2022-11-18T06:07:38Z</dc:date>
    </item>
    <item>
      <title>Re: Users unable to see the dashboards irrespective of permissions / roles enabled</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/What-is-the-issue-with-users-unable-to-see-the-dashboards/m-p/621174#M50993</link>
      <description>&lt;P&gt;OK one final guess, then you may have to give us more information, such as details of the search which is failing!&lt;/P&gt;&lt;P&gt;Does the search contain lookups or macros?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2022 06:16:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/What-is-the-issue-with-users-unable-to-see-the-dashboards/m-p/621174#M50993</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-11-17T06:16:54Z</dc:date>
    </item>
    <item>
      <title>Re: Users unable to see the dashboards irrespective of permissions / roles enabled</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/What-is-the-issue-with-users-unable-to-see-the-dashboards/m-p/621184#M50994</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/251317"&gt;@DineshRaja&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;could you share the savedsearch ?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2022 06:53:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/What-is-the-issue-with-users-unable-to-see-the-dashboards/m-p/621184#M50994</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-11-17T06:53:42Z</dc:date>
    </item>
    <item>
      <title>Re: Users unable to see the dashboards irrespective of permissions / roles enabled</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/What-is-the-issue-with-users-unable-to-see-the-dashboards/m-p/621329#M51006</link>
      <description>&lt;P&gt;Dashboard query :&lt;/P&gt;&lt;P&gt;index="summary_index1" "search_name=summary_index1*" | eval SLR01 = if((duration&amp;gt;1.8 OR duration=0),"Breached","Not Breached") | where LC&amp;gt;1|dedup isoClearSysRef |stats count(eval(SLR01="Breached")) as Transaction_Count, count(SLR01) As Total_Transaction_Count|eval CountStatus= Transaction_Count+"/"+Total_Transaction_Count| table CountStatus&lt;/P&gt;&lt;P&gt;Results = CountStatus 0/0&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Savedsearch for "summary_index1*"&lt;BR /&gt;index="test_index1" sourcetype="test_sourcetype" queueName=queue1 OR queueName=queue2 OR queueName= queue3 | rename isoMsgDefId as MD, queueName as QN | eval MD1=split(MD,"."), QN1=split(QN,"."), MD2=mvindex(MD1,0), MD3=mvindex(MD1,1) ,QN2=mvindex(QN1,5), pacs=MD2+MD3, ID4= coalesce(isoInstructionId,isoOriginalInstructionId)| sort 0 timeStamp | dedup isoClearSysRef pacs sortby +_time| search NOT (pacs="pain001" OR pacs="pain002") | eval Time=strftime(timeStamp,"%m/%d/%Y %H:%M:%S.%Q")| transaction isoClearSysRef keepevicted=true | streamstats count by QN2 | where linecount&amp;gt;1 | eval "OLA Status" = if((duration&amp;gt;1.3 OR linecount&amp;lt;2),"Breached","Not Breached") | rename isoClearSysRef as PaymentID pacs as "Exit/Entry" duration as "OLA (sec)", QN as queueName, timeStamp as "Time Stamp" ID4 as "isoInstructionID" | table "Time Stamp" queueName "Exit/Entry" "OLA (sec)" "OLA Status" PaymentID isoInstructionID | search NOT [search index=summary_index1 search_name=summary_index1| table "OLA (sec)" "OLA Status" PaymentID isoInstructionID ] | collect index=summary_index1 marker="search_name=summary_index1"&lt;/P&gt;&lt;P&gt;Results = No results to summary index.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Nov 2022 02:19:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/What-is-the-issue-with-users-unable-to-see-the-dashboards/m-p/621329#M51006</guid>
      <dc:creator>DineshRaja</dc:creator>
      <dc:date>2022-11-18T02:19:45Z</dc:date>
    </item>
    <item>
      <title>Re: Users unable to see the dashboards irrespective of permissions / roles enabled</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/What-is-the-issue-with-users-unable-to-see-the-dashboards/m-p/621336#M51008</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Here are the searches:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Dashboard query :&lt;/P&gt;&lt;P&gt;index="summary_index1" "search_name=summary_index1*" | eval SLR01 = if((duration&amp;gt;1.8 OR duration=0),"Breached","Not Breached") | where LC&amp;gt;1|dedup isoClearSysRef |stats count(eval(SLR01="Breached")) as Transaction_Count, count(SLR01) As Total_Transaction_Count|eval CountStatus= Transaction_Count+"/"+Total_Transaction_Count| table CountStatus&lt;/P&gt;&lt;P&gt;Results = CountStatus 0/0&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Savedsearch for "summary_index1*"&lt;BR /&gt;index="test_index1" sourcetype="test_sourcetype" queueName=queue1 OR queueName=queue2 OR queueName= queue3 | rename isoMsgDefId as MD, queueName as QN | eval MD1=split(MD,"."), QN1=split(QN,"."), MD2=mvindex(MD1,0), MD3=mvindex(MD1,1) ,QN2=mvindex(QN1,5), pacs=MD2+MD3, ID4= coalesce(isoInstructionId,isoOriginalInstructionId)| sort 0 timeStamp | dedup isoClearSysRef pacs sortby +_time| search NOT (pacs="pain001" OR pacs="pain002") | eval Time=strftime(timeStamp,"%m/%d/%Y %H:%M:%S.%Q")| transaction isoClearSysRef keepevicted=true | streamstats count by QN2 | where linecount&amp;gt;1 | eval "OLA Status" = if((duration&amp;gt;1.3 OR linecount&amp;lt;2),"Breached","Not Breached") | rename isoClearSysRef as PaymentID pacs as "Exit/Entry" duration as "OLA (sec)", QN as queueName, timeStamp as "Time Stamp" ID4 as "isoInstructionID" | table "Time Stamp" queueName "Exit/Entry" "OLA (sec)" "OLA Status" PaymentID isoInstructionID | search NOT [search index=summary_index1 search_name=summary_index1| table "OLA (sec)" "OLA Status" PaymentID isoInstructionID ] | collect index=summary_index1 marker="search_name=summary_index1"&lt;/P&gt;&lt;P&gt;Results = No results to summary index.&lt;BR /&gt;&lt;BR /&gt;Also, I have been seeing below messages on SHC:&lt;BR /&gt;&lt;BR /&gt;Received event for unconfigured/disabled/deleted index=summary_index5 with source="source::sourcexxx" host="host:xxx" sourcetype="sourcetype::stash". So far received events from 7 missing index(es).&lt;BR /&gt;&lt;BR /&gt;Is it something related to this issue?&lt;BR /&gt;note: the index configurations are available on indexers.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Nov 2022 04:02:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/What-is-the-issue-with-users-unable-to-see-the-dashboards/m-p/621336#M51008</guid>
      <dc:creator>DineshRaja</dc:creator>
      <dc:date>2022-11-18T04:02:50Z</dc:date>
    </item>
    <item>
      <title>Re: Users unable to see the dashboards irrespective of permissions / roles enabled</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/What-is-the-issue-with-users-unable-to-see-the-dashboards/m-p/621344#M51010</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/251317"&gt;@DineshRaja&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;only one additional question: does your search run with another user?&lt;/P&gt;&lt;P&gt;because I see in the generating search the you save in the summary index the following fields:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| table "Time Stamp" queueName "Exit/Entry" "OLA (sec)" "OLA Status" PaymentID isoInstructionID&lt;/LI-CODE&gt;&lt;P&gt;but in the dashboard search you call other fields not present in the summary index: duration,&amp;nbsp;&lt;SPAN&gt;LC,&amp;nbsp;isoClearSysRef; you shouldn't have them!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;at least, why do you use quote for the main search of you dashboard?&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;"search_name=summary_index1*"&lt;/LI-CODE&gt;&lt;P&gt;In this way you search as a string not as a field.&lt;/P&gt;&lt;P&gt;Start you debugging from this second item and then modify the generating search.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 18 Nov 2022 07:31:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/What-is-the-issue-with-users-unable-to-see-the-dashboards/m-p/621344#M51010</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-11-18T07:31:49Z</dc:date>
    </item>
    <item>
      <title>Re: Users unable to see the dashboards irrespective of permissions / roles enabled</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/What-is-the-issue-with-users-unable-to-see-the-dashboards/m-p/621522#M51017</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Thanks for the info. I don't know the exact logic behind the search or dashboard as they were created by Dev team.&amp;nbsp;&lt;BR /&gt;As an Admin I need to resolve the issue why users are unable to see the values in dashboards. Also, as updated in my previous comments, the search is running perfectly fine &amp;amp; fetching the results as per requirement when I logged in as admin user.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Nov 2022 06:05:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/What-is-the-issue-with-users-unable-to-see-the-dashboards/m-p/621522#M51017</guid>
      <dc:creator>DineshRaja</dc:creator>
      <dc:date>2022-11-21T06:05:20Z</dc:date>
    </item>
    <item>
      <title>Re: Users unable to see the dashboards irrespective of permissions / roles enabled</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/What-is-the-issue-with-users-unable-to-see-the-dashboards/m-p/621848#M51042</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Could you please help with your inputs if possible ?&lt;BR /&gt;Just looking out for some sort of help.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 12:29:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/What-is-the-issue-with-users-unable-to-see-the-dashboards/m-p/621848#M51042</guid>
      <dc:creator>DineshRaja</dc:creator>
      <dc:date>2022-11-23T12:29:10Z</dc:date>
    </item>
    <item>
      <title>Re: Users unable to see the dashboards irrespective of permissions / roles enabled</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/What-is-the-issue-with-users-unable-to-see-the-dashboards/m-p/621849#M51043</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/251317"&gt;@DineshRaja&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;let me summarize the issue:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;you have a scheduled search that saves in an index (called &lt;SPAN&gt;summary_index1&amp;nbsp;)&amp;nbsp;&lt;/SPAN&gt;the following fields:&amp;nbsp;&lt;SPAN&gt;"Time Stamp" queueName "Exit/Entry" "OLA (sec)" "OLA Status" PaymentID isoInstructionID,&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;if you run the above search, you see the results, but when you add the collect command, the first search doesn't give any result;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;the question is: do you see events in the summary index running only the main search (index="summary_index1" "search_name=summary_index1*"&amp;nbsp;)?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If yes, you have to debug the search on the summary index, because probably the error is in the coditions of this search.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;if not you have to debug the scheduled search because the problem is in the collect command (if you have results without the collect command) or in the conditions (if you haven't results without the collect command).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 12:53:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/What-is-the-issue-with-users-unable-to-see-the-dashboards/m-p/621849#M51043</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-11-23T12:53:51Z</dc:date>
    </item>
  </channel>
</rss>

