Dashboards & Visualizations

Preview in dashboard works only for some users ?

alexantao
Path Finder

In splunk 6.0, I created two Saved Searches.

I have an user with admin access and another user with user access (I don't know if it really matters in this case).

I created a dashboard with 4 panels, the last 2 are Pivot graphics. The first two panels are reports based on these 2 saved searches I created.

The problem is that when I open the dashboard with the user with "user" level access, one of then is shown as the search is being executed, but the other does not, only the Loadng 0% and the panel is shown. No errors are presented. If I open the same dashboard with the user with admin access, both panels are shown as the search is being executed.

Inspecting the job, BOTH has the isPreviewEnabled=False, and cannot find anywhere to enable it.

I've created a third search to test, similar to the one that has a problem, and nothing changed.

My searches are configured as:

    Search-Problem    2013-10-12 00:00:00 BRT  flashtimeline user Clients 0 Global
    Search-probl-new  None                     None      user Clients 0 Global
    Search-OK     2013-10-12 00:00:00 BRT  None      user Clients 0 Global

Please, How can I make all reports preview the results as the seach is being executed ?

Thanks a lot !

Tags (3)
0 Karma

ziegfried
Influencer

My suspicion is that the limit on current searches for the user role (3 by default) causes the job driving one of the panels to be queued. It's not possible to preview a job as long as it's queued.

You could try to increase the limit in Settings -> Access Controls -> Roles.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...