Dashboards & Visualizations

Dashboard Studio working with Reports and Time Range New question

Cheng2Ready
Communicator

Dashboard Studio working with Reports and Time Range

@sainag_splunk 

I am currently using the new dashboard studio interface, they make calls to saved reports in Splunk.

Is there a way to have time range work for the dashboard, but also allow it to work with the reports?

The issue we face is 
we are able to set the reports in the studio dashboard, but the default is that they are stuck as static reports.

how can we add in a time range input that will work with the dashboard and the reports?
The users who are viewing this dashboard are third party and people that we do not want to give access to the Index (example... outside of the Org users)

hence the reason the dashboard used saved reports where its viewable, but like I mentioned we faced the issue of changing the Time range picker since the saved reports are showing in a static, where we wish to make it  change as we specify a time range with the Input.

we are trying to not give third party users access to Splunk Indexes

Also tried looking into Embedded reports but found
" Embedded reports also cannot support real-time searches."Cheng2Ready_1-1729036521152.png

Labels (1)
0 Karma

sainag_splunk
Splunk Employee
Splunk Employee

Hello @Cheng2Ready 

The global time range picker cannot be applied to saved searches in Dashboard Studio since each saved search has its own predefined time range. Unlike Classic Dashboards, when you reference a Saved Search in Studio, it will always use its own time range settings, ignoring any global time range selections.

For your use case, I recommend:

  1. Schedule a report with your required metrics
  2. Use the '|collect' command to store results in a new index
  3. Create a new role for third-party access that only has permissions for this new index
  4. Optionally, you can:
    • Disable specific capabilities for this role
    • Restrict access to only the required dashboard

This approach helps maintain security by avoiding direct access to the original index.


If this reply helps you. Please UpVote.

If this helps, Upvote!!!!
Together we make the Splunk Community stronger 
0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...