Security

Facing Issues To Run A Report On User Access

saibal6
Path Finder

Hi Experts,

I have admin permission to login into the splunk. So whenever I run a report, it's taking hardly 2 seconds or less than that. So i have shared that report with user only read access mode. But whenever user is trying to run that report it's showing an message that "waiting for queued job to start Manage Jobs".

Could anyone help me on this matter? What should I do in this case or how can I troubleshoot this issue?

If you need more info in this matter, please let me know.

Thanks,
@saibal6

0 Karma

woodcock
Esteemed Legend

The user has used up to much disk quota for his search results. Have him click on the Jobs link and delete all of his search job artifacts and then his search will run. Then educate him not to run searches that generate gobs of results, because this will consume his disk quota.

0 Karma

tom_frotscher
Builder

Hi,

the user role is per default limited to a small amount of searches that run in parallel and the results of a user can also only take limited space in the splunk dispatch folder. The lifetime of a search is 10min. As an example: A user starts a search which returns alot of results, so the 100mb space in the dispatch folder is used up. The user have to wait 10min until the lifetime ends and the search is removed from dispatch folder. You can edit those values in settings -> access control -> roles, there you can select the role you want to edit.

The options "User-level concurrent search jobs limit", "User-level concurrent real-time search jobs limit", and "Limit total jobs disk quota" are of interest in your case. You can increase them, but this will increase the load of your splunk machines if the user make heavy use of more searches.

Greetings

Tom

0 Karma
Get Updates on the Splunk Community!

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...