Dashboards & Visualizations

Identical dashboards displaying differently

kmattern
Builder

I develop on one Splunk instance and then copy the work to another Splunk instance for testing prior to it going into production. To install the app on the test system I tar it up and install it through Manager. I know that all the code on the two machines for this particular app is identical. I have run diffs on everything. So why do they display differently? And, yes, the css is identical on both boxes.

What's really interesting is that some users see the same on both machines; the one shown in test below. And one person sees the same on both machines but sees what is shown in the dev screenshot below. To the best of my knowledge I am the only one who sees different dashboards on each box.

When drilling down from the first dashboard the second will display two panels when only one is referenced in the XML. I have close to 200 dashboards and this is the only one that is acting up.

Any ideas will be helpful. This is too bizarre.

This is the dashboard on Dev
alt text

This is the same dashboard on the Test box
alt text

Tags (1)

sideview
SplunkTrust
SplunkTrust

If you're each using your own user accounts when accessing the instances, I'm guessing that sometimes there's a version of the app saved to the /local directory in the app, or to the etc/users/<username>/<appname>/ directory. If so then either of those would be overriding the default XML at the app level, and that's the only thing that could explain the different number of panels. And if css tweaks were ever made in the dashboards it could explain that too.

0 Karma

kmattern
Builder

That's what I thought. But I looked for duplicates and found none.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...