Splunk Enterprise Security

Splunk dashboard user session never expires

cyber_castle
Path Finder

Hello guys,

We are using SH Clustering with Eneterprise SEcurity with F5 Load balancer. We have a requirement from our SOC team to display the dashboard on the TV - 24/7 so that they can monitor it continuously. Our users are connected through LDAP. I am aware off the setting - ui_inactivity_timeout in web.conf to zero so that it will never expires.

  1. We want to create only for one generic_user (soc_anaylsts) which is in the AD.
  2. If we have to create the user locally in the SH, will it work as we have a Load balancer and as far as i know, it will create only on one SH not on all.

Pls help

0 Karma

cyber_castle
Path Finder

@sir_lamneth - thanks for EmbedScheduledreports. Let me test this in our environment and will let you know.

0 Karma

cyber_castle
Path Finder

I have tried that script, for some reason its not working for me. May be is it because, it may have written for an older version of browser/splunk version?

0 Karma

sir_lamneth
Explorer

If you want to create a non-LDAP user, then you can do this in a Cluster. If you follow these instructions, then it will get replicated across the Cluster:

https://docs.splunk.com/Documentation/Splunk/7.2.0/DistSearch/AdduserstotheSHC

Another option is to embed the Report or Dashboard within another site.

https://docs.splunk.com/Documentation/Splunk/latest/Report/Embedscheduledreports

https://answers.splunk.com/answers/153158/feature-request-how-to-embed-a-dashboard-not-a-rep.html

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...