Dashboards & Visualizations

Why is report acceleration on a dashboard working for one role, but not another?

hqw
Path Finder

Hi all,

I have dashboards which used post process search as global search, and acceleration report on that global search. in this case, the dashboard is working very fast when I open It. However, I have multiple accounts belonging to different roles to access these dashboards. When I tried with role1, the dashboard acceleration is working, but when I tried another account, which is under role2, the acceleration report is not working, and the dashboard became very slow.

These two roles have different capabilities. May I know if it is due to that issue? and how can I fix this?
Thanks in advance.

Best Regards

0 Karma
1 Solution

mreynov_splunk
Splunk Employee
Splunk Employee

permissions would be the first place I would look. Under Settings->Users and Authentication->Access Controls->Roles-> there is a section "Capabilities". Check whether "accelerate_datamodel" is checked.alt text

View solution in original post

mreynov_splunk
Splunk Employee
Splunk Employee

permissions would be the first place I would look. Under Settings->Users and Authentication->Access Controls->Roles-> there is a section "Capabilities". Check whether "accelerate_datamodel" is checked.alt text

hqw
Path Finder

Hi Mreynov,

Thanks for your help on this issue. however, both these two roles had accelerate_** capabilities already. The only different is that role1 has admin_all_objective capability, role2 doesn't have this. when i assign this capability to role 2, then the acceleration dashboard will be working also to role2.

Finally, i noticed that the issue was due to the accelerated saved search permission. after i gave the permission to the global, then the dashboard works for any role.

Thanks again for your time and help.

Best Regards

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...