Security

can't run a dashboard with radialGauge?

Conradj
Path Finder

Hi,

I have a dashboard that shows me some simple metrics in real-time. These are displayed as a mixture of "single" values and "radialGauges"

I have created a special user to use to view this dashboard who has restricted rights.
The have rights to this app only and they are a member of their own role. The user_role I created for them is a member of the "users" and "power" users groups.

The user_role group has the dashboard app as its default, is limited to 12 concurrent search jobs, 12 concurrent real-time search jobs and is limited to 100mb for jobs disk quota.

When I login as my admin user the dashboard runs fine without any errors and the radialgauges appear AOK.

When I login as this user and access the dashboard I get an error in red that states:

"Search Operation 'gauge' is unknown. You might not have permission to run this program."

and the radialGauges do not appear.

In my home.xml (the dashboard view) I have gauge configurations similar to:

<chart>

index="windows_perfmon" host="ps*4sql*" counter="% Processor Time" | stats avg(Value) as CPU | eval CPU=round(CPU,2) | gauge CPU 0 25 75 100
SQL Server CPU Utilisation
rt
rt
radialGauge
minimal

I am using Splunk 4.3.2 Build 123586.

I really don't want to run my dashboard as admin! Anyone have any ideas?

Cheers,

C.

0 Karma

Conradj
Path Finder

derp dee derp

Was using two different browsers to test permissions and such and tried editing the search in-app.

I removed the "| gauge 0 25 75 100" from the end of the searchSstring string (while leaving the vizualization settings alone)

Hey presto it works.

C.

Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...