Splunk Enterprise Security

Splunk dashboard user session never expires

cyber_castle
Path Finder

Hello guys,

We are using SH Clustering with Eneterprise SEcurity with F5 Load balancer. We have a requirement from our SOC team to display the dashboard on the TV - 24/7 so that they can monitor it continuously. Our users are connected through LDAP. I am aware off the setting - ui_inactivity_timeout in web.conf to zero so that it will never expires.

  1. We want to create only for one generic_user (soc_anaylsts) which is in the AD.
  2. If we have to create the user locally in the SH, will it work as we have a Load balancer and as far as i know, it will create only on one SH not on all.

Pls help

0 Karma

cyber_castle
Path Finder

@sir_lamneth - thanks for EmbedScheduledreports. Let me test this in our environment and will let you know.

0 Karma

cyber_castle
Path Finder

I have tried that script, for some reason its not working for me. May be is it because, it may have written for an older version of browser/splunk version?

0 Karma

sir_lamneth
Explorer

If you want to create a non-LDAP user, then you can do this in a Cluster. If you follow these instructions, then it will get replicated across the Cluster:

https://docs.splunk.com/Documentation/Splunk/7.2.0/DistSearch/AdduserstotheSHC

Another option is to embed the Report or Dashboard within another site.

https://docs.splunk.com/Documentation/Splunk/latest/Report/Embedscheduledreports

https://answers.splunk.com/answers/153158/feature-request-how-to-embed-a-dashboard-not-a-rep.html

0 Karma
Get Updates on the Splunk Community!

Best Strategies to Optimize Observability Costs

 Join us on Tuesday, May 6, 2025, at 11 AM PDT / 2 PM EDT for an insightful session on optimizing ...

Fueling your curiosity with new Splunk ILT and eLearning courses

At Splunk Education, we’re driven by curiosity—both ours and yours! That’s why we’re committed to delivering ...

Splunk AI Assistant for SPL 1.1.0 | Now Personalized to Your Environment for Greater ...

Splunk AI Assistant for SPL has transformed how users interact with Splunk, making it easier than ever to ...