Security

can't run a dashboard with radialGauge?

Conradj
Path Finder

Hi,

I have a dashboard that shows me some simple metrics in real-time. These are displayed as a mixture of "single" values and "radialGauges"

I have created a special user to use to view this dashboard who has restricted rights.
The have rights to this app only and they are a member of their own role. The user_role I created for them is a member of the "users" and "power" users groups.

The user_role group has the dashboard app as its default, is limited to 12 concurrent search jobs, 12 concurrent real-time search jobs and is limited to 100mb for jobs disk quota.

When I login as my admin user the dashboard runs fine without any errors and the radialgauges appear AOK.

When I login as this user and access the dashboard I get an error in red that states:

"Search Operation 'gauge' is unknown. You might not have permission to run this program."

and the radialGauges do not appear.

In my home.xml (the dashboard view) I have gauge configurations similar to:

<chart>

index="windows_perfmon" host="ps*4sql*" counter="% Processor Time" | stats avg(Value) as CPU | eval CPU=round(CPU,2) | gauge CPU 0 25 75 100
SQL Server CPU Utilisation
rt
rt
radialGauge
minimal

I am using Splunk 4.3.2 Build 123586.

I really don't want to run my dashboard as admin! Anyone have any ideas?

Cheers,

C.

0 Karma

Conradj
Path Finder

derp dee derp

Was using two different browsers to test permissions and such and tried editing the search in-app.

I removed the "| gauge 0 25 75 100" from the end of the searchSstring string (while leaving the vizualization settings alone)

Hey presto it works.

C.

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...