Dashboards & Visualizations

Dashboard visibility issue

bworrellZP
Communicator

So I had a dashboard that was in testing, so it was private. Since I have completed it, I changed it, made visible in the app (search app), set to everyone for read.

alt text
Then I logged in as a test user. The dashboard is there, all panels are visible. Issue is that everything says "no results found", If I click the spyglass, nothing shows in the statistics, yet there are events in the events tabs.

User that I was testing with is also an admin.

Thoughts on what to check and where?

Tags (1)
0 Karma

ChrisChalmers01
Explorer

You mention that you changed the permissions for the dashboard but did also change the permissions for the reports / searches that power the dashboard?

0 Karma

mayurr98
Super Champion

hey
So for a test user you must have assigned some role. For that role, check if you have given capability to search desired indexes which make that dashboard run
Edit a role using https://docs.splunk.com/Documentation/Splunk/7.0.1/Security/Addandeditroles#Add_or_edit_a_role
and assign Indexes searched by default and indexes a desired index on which the dashboard is built.

I hope that help!

0 Karma

bworrellZP
Communicator

I believe I have found a bug. Test user is in a splunk group that comes from AD, (splunktier3sec), but also inherits some other roles. (User ends up with these roles - admin, power, splunktier3sec ) I had to add the searched indexes by default the indexes in use, to the admin role, even though they were in the splunkteir3sec role already. (Dashboard searches also had the indexes listed, so it should not have been needed anyway). Guess that role trumps all others.

Will test later with non-admin, with only one role. But at this point, I believe this to be the case.

0 Karma

mayurr98
Super Champion

Yes test later with non-admin
Also test by creating role Access controls » Roles and assign the desired capabilities and create a test user using Access controls » Users

mayurr98
Super Champion

Please accept/upvote my answer for future readers if you feel its correct!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...