Dashboards & Visualizations

Dashboard Studio working with Reports and Time Range New question

Cheng2Ready
Path Finder

Dashboard Studio working with Reports and Time Range

@sainag_splunk 

I am currently using the new dashboard studio interface, they make calls to saved reports in Splunk.

Is there a way to have time range work for the dashboard, but also allow it to work with the reports?

The issue we face is 
we are able to set the reports in the studio dashboard, but the default is that they are stuck as static reports.

how can we add in a time range input that will work with the dashboard and the reports?
The users who are viewing this dashboard are third party and people that we do not want to give access to the Index (example... outside of the Org users)

hence the reason the dashboard used saved reports where its viewable, but like I mentioned we faced the issue of changing the Time range picker since the saved reports are showing in a static, where we wish to make it  change as we specify a time range with the Input.

we are trying to not give third party users access to Splunk Indexes

Also tried looking into Embedded reports but found
" Embedded reports also cannot support real-time searches."Cheng2Ready_1-1729036521152.png

Labels (1)
0 Karma

sainag_splunk
Splunk Employee
Splunk Employee

Hello @Cheng2Ready 

The global time range picker cannot be applied to saved searches in Dashboard Studio since each saved search has its own predefined time range. Unlike Classic Dashboards, when you reference a Saved Search in Studio, it will always use its own time range settings, ignoring any global time range selections.

For your use case, I recommend:

  1. Schedule a report with your required metrics
  2. Use the '|collect' command to store results in a new index
  3. Create a new role for third-party access that only has permissions for this new index
  4. Optionally, you can:
    • Disable specific capabilities for this role
    • Restrict access to only the required dashboard

This approach helps maintain security by avoiding direct access to the original index.


If this reply helps you. Please UpVote.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...