Splunk Search

Dashboard_live not showing all data after license change

asmithe
Path Finder

After upgrading license from free to enterprise, the default search dashboard displayed no data.

Search on Splunk Answers revealed nothing specific to this problem.

Found a related problem in this answer, and turns out if you check out the user roles and mistakenly click on something then try to use the browser back button, you may still change some of the default settings.

0 Karma
1 Solution

asmithe
Path Finder

In user roles, make sure to set "Indexes searched by default" to include whichever indices you want searched in dashboard_live.

View solution in original post

0 Karma

asmithe
Path Finder

In user roles, make sure to set "Indexes searched by default" to include whichever indices you want searched in dashboard_live.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...