Dashboards & Visualizations

Dashboard visibility issue

bworrellZP
Communicator

So I had a dashboard that was in testing, so it was private. Since I have completed it, I changed it, made visible in the app (search app), set to everyone for read.

alt text
Then I logged in as a test user. The dashboard is there, all panels are visible. Issue is that everything says "no results found", If I click the spyglass, nothing shows in the statistics, yet there are events in the events tabs.

User that I was testing with is also an admin.

Thoughts on what to check and where?

Tags (1)
0 Karma

ChrisChalmers01
Explorer

You mention that you changed the permissions for the dashboard but did also change the permissions for the reports / searches that power the dashboard?

0 Karma

mayurr98
Super Champion

hey
So for a test user you must have assigned some role. For that role, check if you have given capability to search desired indexes which make that dashboard run
Edit a role using https://docs.splunk.com/Documentation/Splunk/7.0.1/Security/Addandeditroles#Add_or_edit_a_role
and assign Indexes searched by default and indexes a desired index on which the dashboard is built.

I hope that help!

0 Karma

bworrellZP
Communicator

I believe I have found a bug. Test user is in a splunk group that comes from AD, (splunktier3sec), but also inherits some other roles. (User ends up with these roles - admin, power, splunktier3sec ) I had to add the searched indexes by default the indexes in use, to the admin role, even though they were in the splunkteir3sec role already. (Dashboard searches also had the indexes listed, so it should not have been needed anyway). Guess that role trumps all others.

Will test later with non-admin, with only one role. But at this point, I believe this to be the case.

0 Karma

mayurr98
Super Champion

Yes test later with non-admin
Also test by creating role Access controls » Roles and assign the desired capabilities and create a test user using Access controls » Users

mayurr98
Super Champion

Please accept/upvote my answer for future readers if you feel its correct!

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...