Dashboards & Visualizations

Dashboard Studio working with Reports and Time Range New question

Cheng2Ready
Communicator

Dashboard Studio working with Reports and Time Range

@sainag_splunk 

I am currently using the new dashboard studio interface, they make calls to saved reports in Splunk.

Is there a way to have time range work for the dashboard, but also allow it to work with the reports?

The issue we face is 
we are able to set the reports in the studio dashboard, but the default is that they are stuck as static reports.

how can we add in a time range input that will work with the dashboard and the reports?
The users who are viewing this dashboard are third party and people that we do not want to give access to the Index (example... outside of the Org users)

hence the reason the dashboard used saved reports where its viewable, but like I mentioned we faced the issue of changing the Time range picker since the saved reports are showing in a static, where we wish to make it  change as we specify a time range with the Input.

we are trying to not give third party users access to Splunk Indexes

Also tried looking into Embedded reports but found
" Embedded reports also cannot support real-time searches."Cheng2Ready_1-1729036521152.png

Labels (1)
0 Karma

sainag_splunk
Splunk Employee
Splunk Employee

Hello @Cheng2Ready 

The global time range picker cannot be applied to saved searches in Dashboard Studio since each saved search has its own predefined time range. Unlike Classic Dashboards, when you reference a Saved Search in Studio, it will always use its own time range settings, ignoring any global time range selections.

For your use case, I recommend:

  1. Schedule a report with your required metrics
  2. Use the '|collect' command to store results in a new index
  3. Create a new role for third-party access that only has permissions for this new index
  4. Optionally, you can:
    • Disable specific capabilities for this role
    • Restrict access to only the required dashboard

This approach helps maintain security by avoiding direct access to the original index.


If this reply helps you. Please UpVote.

If this helps, Upvote!!!!
Together we make the Splunk Community stronger 
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...