Dashboards & Visualizations

Why are users not able to see graphs in Dashboard after creating a field extraction?

NeerajDhapola7
Path Finder

Step 1: fields were extracted using separator (,) with Splunk's delimiter and fields name were like starttime,errordate,instance,proxy,filename .....etc

Due to some issue, separator was updated from comma , to pipe |.

Step2 : Deleted previous field extraction and created new field extraction using separator(|) with same name of fields.

Step 3: Permission is updated from private to APP wth READ only to everyone.

Step 4 : Again going back to existing dashboard i am able to view all graph with latest data.

Issue : other User not able to view existing dashboard graphs.
in some post it was suggested to update permission for field transformation, but i am not getting any field transformation which is created by me.

Please let me know if any more clarification required.

Thanks
Neeraj Singh Dhapola

0 Karma

woodcock
Esteemed Legend

You need to have your admin restart splunk in the next maintenance window.

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Are you using the same sourcetype for the new field you made?

0 Karma

NeerajDhapola7
Path Finder

yes same sourcetype or index
As I can see the results that means query is working.
Issue is only with VIEW (Permission) for other users which I have given already in field extration

0 Karma

woodcock
Esteemed Legend

Did you restart splunk on the search head or do a debug/refresh?

0 Karma

NeerajDhapola7
Path Finder

I am normal power user don't have admin rights or cant restart the search head.
Please let me know how can I do debug and refresh.

Appreciates for the response.

0 Karma

skoelpin
SplunkTrust
SplunkTrust

http://splunkURL:port/debug/refresh

Hit the refresh button and it will give you a list of all the configs that were refreshed (Some things will require a Splunkd restart)

0 Karma

NeerajDhapola7
Path Finder

yes i tried same after getting your post but i am getting below response i think admin only can do

response>
messages>
msg type="ERROR">Forbidden
/messages>

/response>

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...