Dashboards & Visualizations

Dashboard visibility issue

bworrellZP
Communicator

So I had a dashboard that was in testing, so it was private. Since I have completed it, I changed it, made visible in the app (search app), set to everyone for read.

alt text
Then I logged in as a test user. The dashboard is there, all panels are visible. Issue is that everything says "no results found", If I click the spyglass, nothing shows in the statistics, yet there are events in the events tabs.

User that I was testing with is also an admin.

Thoughts on what to check and where?

Tags (1)
0 Karma

ChrisChalmers01
Explorer

You mention that you changed the permissions for the dashboard but did also change the permissions for the reports / searches that power the dashboard?

0 Karma

mayurr98
Super Champion

hey
So for a test user you must have assigned some role. For that role, check if you have given capability to search desired indexes which make that dashboard run
Edit a role using https://docs.splunk.com/Documentation/Splunk/7.0.1/Security/Addandeditroles#Add_or_edit_a_role
and assign Indexes searched by default and indexes a desired index on which the dashboard is built.

I hope that help!

0 Karma

bworrellZP
Communicator

I believe I have found a bug. Test user is in a splunk group that comes from AD, (splunktier3sec), but also inherits some other roles. (User ends up with these roles - admin, power, splunktier3sec ) I had to add the searched indexes by default the indexes in use, to the admin role, even though they were in the splunkteir3sec role already. (Dashboard searches also had the indexes listed, so it should not have been needed anyway). Guess that role trumps all others.

Will test later with non-admin, with only one role. But at this point, I believe this to be the case.

0 Karma

mayurr98
Super Champion

Yes test later with non-admin
Also test by creating role Access controls » Roles and assign the desired capabilities and create a test user using Access controls » Users

mayurr98
Super Champion

Please accept/upvote my answer for future readers if you feel its correct!

0 Karma
Get Updates on the Splunk Community!

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...

Splunkbase | Splunk Dashboard Examples App for SimpleXML End of Life

The Splunk Dashboard Examples App for SimpleXML will reach end of support on Dec 19, 2024, after which no new ...

Understanding Generative AI Techniques and Their Application in Cybersecurity

Watch On-Demand Artificial intelligence is the talk of the town nowadays, with industries of all kinds ...