Dashboards & Visualizations

How can a restricted user to view a custom app's dashboard, which contains a lookup definition from an app that the user does not have access to?

adamsmith47
Communicator

My question is very similar to this one: https://answers.splunk.com/answers/227852/is-it-possible-to-use-a-lookup-table-defined-in-on.html
which has been answered, but mine is subtly different.

In my scenario, I have a restricted_role, which, off all the apps, only has access to a custom_app (I do not want the restricted_role to have access to the Search and Reporting app). In the Search and Reporting app, there is a lookup_table and lookup_definition, both of which have permissions set to Global (all apps), Everyone can Read. However, the dashboard panels in my custom_app which reference the lookup_definition fail to run, with:

"Error in 'lookup' command. The lookup table 'lookup_definition' does not exist or is not available."

If I extend the permissions for the Search and Reporting app to include restricted_role, the panels run fine. However, I do not want this role to have access to the Search and Reporting app.

I'm looking for advice for how to resolve this. I know I could create a new lookup_file and lookup_definition in the custom_app, but, I'd prefer not to have duplicate knowledge objects to maintain. Any advice is welcome. Thank you.

0 Karma

snoobzilla
Builder

Have you tried creating up a lookup definition in the target app against the global lookup table? Then at least it same underlying file and you won't have maintain 2 copies of the data.

I have had good luck on global lookups by creating them using the outputlookup command. If above doesn't work, try making a copy of table using outputlookup and point a lookup definition from each app at the new file.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...