Security

Admin account to view all the Dashboard created by individual users

Nvijay92
Explorer

Hello Everyone,

 

We are having a situation on our Splunk system.

We recently noticed that there are several Dashboards which are being created by users and shared only for them.

Being an Administrator to the Splunk system we are unable to view those Dashboards in normal way until we query those Dashboard via rest.

Is there anyway to set view access for Administrator role to view all the Dashboards/reports/alerts/scheduled search that are being created by users

Thank you

Labels (2)
0 Karma

rupkumar4sec
Path Finder

I think if he got Admin access, he should be able to see from both the locations. 
Please correct me if I am wrong.

0 Karma

AKG1_old1
Builder

I agree that admin should be able to access all the dasboards but  thats not the case. I  am admin and not be able to access private dashboard created by other users.  Even when I access through URL its through error "Page not found". I tried to add few more roles/capabilities in Admin but didn't work.

0 Karma

rupkumar4sec
Path Finder

Did you check in the all configurations as @isoutamo mentioned? 

I think something else got messed up with your roles. Trying adding "admin_all_objects" if it not preset already. 

0 Karma

AKG1_old1
Builder

Yes workaround suggested by @isoutamo  worked like a charm.   I was able to change permission from settings>user interface>views. Just wondering why Admin doen't have permission to access it by default.

And admin_all_objects was alredy present. I think this is the default behavior. I check in mulitple installation and everywhere its same.

0 Karma

isoutamo
SplunkTrust
SplunkTrust

This is valid also with admin role. Via views you could see only your own or app/globally shared dashboards, but not anyone’s private KOs.

rupkumar4sec
Path Finder

You should be able to see them by going to

settings>User Interface>Views

isoutamo
SplunkTrust
SplunkTrust

You couldn’t see those private KO e.g. dashboards via this path. The only way is see those via all KOs.

r. Is,o

0 Karma

AKG1_old1
Builder

Hi,

I am looking for the same. Did you find a solution.

Thanks

0 Karma

isoutamo
SplunkTrust
SplunkTrust

You can see those via settings -> all knowledge object (or something similar).

r. Ismo

AKG1_old1
Builder

Thank you!

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...