Step 1: fields were extracted using separator (,) with Splunk's delimiter and fields name were like starttime,errordate,instance,proxy,filename .....etc
Due to some issue, separator was updated from comma , to pipe |.
Step2 : Deleted previous field extraction and created new field extraction using separator(|) with same name of fields.
Step 3: Permission is updated from private to APP wth READ only to everyone.
Step 4 : Again going back to existing dashboard i am able to view all graph with latest data.
Issue : other User not able to view existing dashboard graphs.
in some post it was suggested to update permission for field transformation, but i am not getting any field transformation which is created by me.
Please let me know if any more clarification required.
Thanks
Neeraj Singh Dhapola
You need to have your admin restart splunk in the next maintenance window.
Are you using the same sourcetype for the new field you made?
yes same sourcetype or index
As I can see the results that means query is working.
Issue is only with VIEW (Permission) for other users which I have given already in field extration
Did you restart splunk on the search head or do a debug/refresh
?
I am normal power user don't have admin rights or cant restart the search head.
Please let me know how can I do debug and refresh.
Appreciates for the response.
http://splunkURL:port/debug/refresh
Hit the refresh button and it will give you a list of all the configs that were refreshed (Some things will require a Splunkd restart)
yes i tried same after getting your post but i am getting below response i think admin only can do
response>
messages>
msg type="ERROR">Forbidden
/messages>