All Apps and Add-ons

Dashbord shows different results to different users

discoverneeraj
Explorer

Hello All,
I executed the following search and saved it as a dashboard:

index="tcpr-dispatcher" host="orl_displogs" sourcetype=DispatcherLogs Module=proetojt OR Module=nxtransdirect OR
Module=sep_cid_coversheet OR Module=previewservice | chart count by Module, field3

It gives correct results to me. However it gives different set of results when my colleagues view it.

The issue is that field3 field does not come up when the other colleagues perform the search. We are unable to figure out how a particular field is displayed for one user and not for other. We have checked that field3 is not defined specifically for me in the following:

  1. Field Aliases
  2. Calculated Fields
  3. Field Extractions
  4. Field Transformations
  5. Sourcetype renaming
  6. Workflow actions

We are basically trying to find out that how the dashboard or search is picking up some fields which are displayed only to one user.

Any pointers to solve this issue would be helpful.

Regards,
Neeraj Gupta

Tags (2)
0 Karma

discoverneeraj
Explorer

The roles and the time period is same. While doing troubleshooting with the colleagues, we found the root cause of this issue. I deleted all my previous reports, extracted fields and dashboards.

Next when I performed the search, it was showing only few fields and then we extracted more fields from the search (using delimiter / regex).

When in the last you save this Report-XXXXXXX part i.e. extracted fields, you must give read permissions to all users explicitly.

Thanks for your time and effort to work on my issue.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi discoverneeraj,
the first thing to check is obviously what are roles of your users and that all your knowledge objects are shared for these roles, probably someone of them has different properties.

The second check to do is that the time period is the same in the compared searches (e.g. yesterday or last full hour), because if you use e.g. last hour (that means earliest=-60m latest=now), probably you'll have different results running searches in different times because you'll have different time periods.

Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...