Archive

Add navigation to a Splunk app

Engager

I've added a new view name by editing the default.xml via Splunk Web as an admin, restarted Splunk after and refreshed the instance using /debug/refresh but the new view name is not being added. Is there something i need to do i am missing?

0 Karma

Motivator

@francisc - Even you don't need to do debug refresh when you change it from Splunk web.
Just make sure for App you are updating nav in that App only you are checking the navigation.
Make sure navigation permission/visibility is "Only in this App".
By looking at your xml content here, just make sure you have <nav> as root tag in your xml.

Engager

@VatsalJagani, i did a test using my dev box using a test_app which has the nav tag and i am getting the same results. Sharing is app and permissions are read for everyone and write for admin.

0 Karma

Motivator

I'm afraid then it should work. Just to make sure that you are not getting any error while saving the navigation.

0 Karma

SplunkTrust
SplunkTrust

Looks correct to me, the view should appear in the account control collection for users that can see the view.

0 Karma

Engager

@martin_mueller, where do you configure users to see the views.

0 Karma

SplunkTrust
SplunkTrust

Which view did you add? Did you make sure the view id is spelled correctly?

0 Karma

Engager

Yes i followed the one on top,

view name changed is user_group_changes from the xml

0 Karma

SplunkTrust
SplunkTrust

Post your navigation XML, and make sure the view id is spelled correctly.

0 Karma

Engager
<view name="flashtimeline" />
<collection label="Splunk health">
    <view name="license_usage" />
    <view name="data_inputs_health" />
</collection>
<collection label="Access">
    <view name="authentication_summary" default='true' />
    <view name="hp-ux_authentication" />
    <view name="hp-ux_sudo" />
    <view name="aix_authentication" />
    <view name="aix_sudo" />
</collection>
<collection label="Account control">
    <view name="user_account_changes" />
    <view name="user_group_changes" />
</collection>
<collection label="Auditing">
    <view name="cron_jobs" />
    <view name="ssh_non_interactive_commands" />
    <view name="windows_file_audit" />
</collection>
<collection label="Reports">
<collection label="User Audit">
    <collection label="HP-UX">
  <saved source="unclassified" match="HPux_report" />
    </collection>
    <collection label="AIX">
  <saved source="unclassified" match="AIX_report" />
    </collection>
    <collection label="Windows">
       <view name="report1" />
       <view name="report2" />
       <view name="report3" />
       <view name="report4" />
    </collection>
</collection>

<collection label="Searches">
<collection label="**">
  <saved source="unclassified" match="Syslog" />
</collection>
</collection>    

The view that i have added is user_group_changes which is not showing on the dashboard.

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!