Dashboards & Visualizations

Why are users not able to see graphs in Dashboard after creating a field extraction?

NeerajDhapola7
Path Finder

Step 1: fields were extracted using separator (,) with Splunk's delimiter and fields name were like starttime,errordate,instance,proxy,filename .....etc

Due to some issue, separator was updated from comma , to pipe |.

Step2 : Deleted previous field extraction and created new field extraction using separator(|) with same name of fields.

Step 3: Permission is updated from private to APP wth READ only to everyone.

Step 4 : Again going back to existing dashboard i am able to view all graph with latest data.

Issue : other User not able to view existing dashboard graphs.
in some post it was suggested to update permission for field transformation, but i am not getting any field transformation which is created by me.

Please let me know if any more clarification required.

Thanks
Neeraj Singh Dhapola

0 Karma

woodcock
Esteemed Legend

You need to have your admin restart splunk in the next maintenance window.

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Are you using the same sourcetype for the new field you made?

0 Karma

NeerajDhapola7
Path Finder

yes same sourcetype or index
As I can see the results that means query is working.
Issue is only with VIEW (Permission) for other users which I have given already in field extration

0 Karma

woodcock
Esteemed Legend

Did you restart splunk on the search head or do a debug/refresh?

0 Karma

NeerajDhapola7
Path Finder

I am normal power user don't have admin rights or cant restart the search head.
Please let me know how can I do debug and refresh.

Appreciates for the response.

0 Karma

skoelpin
SplunkTrust
SplunkTrust

http://splunkURL:port/debug/refresh

Hit the refresh button and it will give you a list of all the configs that were refreshed (Some things will require a Splunkd restart)

0 Karma

NeerajDhapola7
Path Finder

yes i tried same after getting your post but i am getting below response i think admin only can do

response>
messages>
msg type="ERROR">Forbidden
/messages>

/response>

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...