Splunk Enterprise Security

Splunk dashboard user session never expires

cyber_castle
Path Finder

Hello guys,

We are using SH Clustering with Eneterprise SEcurity with F5 Load balancer. We have a requirement from our SOC team to display the dashboard on the TV - 24/7 so that they can monitor it continuously. Our users are connected through LDAP. I am aware off the setting - ui_inactivity_timeout in web.conf to zero so that it will never expires.

  1. We want to create only for one generic_user (soc_anaylsts) which is in the AD.
  2. If we have to create the user locally in the SH, will it work as we have a Load balancer and as far as i know, it will create only on one SH not on all.

Pls help

0 Karma

cyber_castle
Path Finder

@sir_lamneth - thanks for EmbedScheduledreports. Let me test this in our environment and will let you know.

0 Karma

cyber_castle
Path Finder

I have tried that script, for some reason its not working for me. May be is it because, it may have written for an older version of browser/splunk version?

0 Karma

sir_lamneth
Explorer

If you want to create a non-LDAP user, then you can do this in a Cluster. If you follow these instructions, then it will get replicated across the Cluster:

https://docs.splunk.com/Documentation/Splunk/7.2.0/DistSearch/AdduserstotheSHC

Another option is to embed the Report or Dashboard within another site.

https://docs.splunk.com/Documentation/Splunk/latest/Report/Embedscheduledreports

https://answers.splunk.com/answers/153158/feature-request-how-to-embed-a-dashboard-not-a-rep.html

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...